Orkestia
Blog
Vault

Secrets

Store a secret at a path, keep its versions, reveal it to the person who asks, and delete, restore or destroy it

A secret is a value stored at a path, such as aws/prod/deploy or stripe/test/api-key. Each change adds a version, and the Vault keeps the latest ones (10 by default) so you can go back.

Paths

  • Separate parts with /: team/service/name.
  • Use letters, digits and _ . @ = + -.
  • Plan paths around who needs access. Policies grant access by path, so payments/** is easy to grant.

Add a secret

In the Console: Vault → Secrets → + Add secret. Enter a path, the value and an optional description.

From the API or an assistant, start vault.secret.write:

InputMeaning
pathWhere to store it
valueThe secret, up to 64 KiB
casOptional safe update. 0 = create only. N = write only if the current version is N
descriptionWhat the secret is for
custom_metadataLabels. These are not secret: never put secret material here
max_versionsVersions to keep, 1 to 100 (default 10)
From scripts and agents, pass cas. If someone else changed the secret in the meantime, the write fails with VAULT_CONFLICT instead of overwriting their change.

Write a new version

In the Console, open the secret's Manage menu and choose New version. From the API, call vault.secret.write again on the same path. Earlier versions stay available.

Reveal a value

vault.secret.read shows the value once, to the person who asked. In the Console it appears in a dialog you can copy from, and is gone when you close it. Pass version to reveal an earlier one.

Every reveal is recorded in the audit log.

If a workflow or agent only needs to call an API with the secret, give it API access instead. It then never sees the value.

Use a secret in a workflow

vault.secret.resolve passes a secret to a step inside one of your workflows without showing it to anyone. It needs the resolve permission and cannot be started directly from the API.

List and inspect

  • vault.secret.list shows the paths you are allowed to see, never values. Filter with prefix.
  • vault.secret.metadata.get shows one secret's versions, labels, API access settings, and who created and last changed it.

Delete, restore, destroy

WorkflowWhat it doesUndo
vault.secret.deleteHides versions. They cannot be read or usedvault.secret.undelete
vault.secret.undeleteRestores deleted versions—
vault.secret.destroyErases versions for goodNone
vault.secret.metadata.deleteRemoves the secret and every versionNone

These act on the current version unless you pass versions.

In the Console, Delete removes the secret and all its versions. Anything that uses it stops working.