Skip to main content
Version: v0.25.0 (Latest)

Secrets: Storage

Catalog id: resource.secrets.storage

Which backend currently holds secrets for the scope you are in. A tenant has exactly one active assignment, and everything that creates a secret handle or resolves a stored credential goes through it. The platform has its own storage for bootstrap secrets and platform-operated integrations.

The screen is deliberately thin. Choosing a different backend is a migration rather than an edit, and that lives on Provider and Migrations.

Audience: tenant administrator for the tenant scope, platform operator for the platform scope.

Guide: Secrets and KMS providers.

Reading the current assignment​

1

The tenant's assignment

GET /api/platform/config/v1/tenants/00000000-0000-4000-8000-000000000000/secrets/assignment200 OK

The assignment carries a display name, the provider type, the lifecycle state, and source, which says whether the backend came from a platform offering or is one the tenant runs itself. The captured tenant uses a platform offering.

source decides who rotates the credential behind it. A platform offering rotates on the platform side and the tenant does nothing; a tenant-managed provider rotates from the tenant's own Provider tab.

version is what a conditional write needs, so read before you write. Mutations use If-Match with a strong ETag, and two operators editing the same assignment get a conflict rather than one silently overwriting the other.

An assignment that is missing or unhealthy does not stop forms from opening. Email accounts and connectors still save and still validate, then fail when they actually need a secret. That is why this is the first screen to check when something that stores a credential misbehaves.

The tenant's assignment
2

The platform's own storage

GET /api/platform/admin/v1/application/secrets/storage200 OK

Switch the tenant picker to platform and the same area shows the platform's assignment. The captured deployment uses environment storage with readOnly: true, which is the normal shape for a packaged deploy: values arrive from deployment configuration, so the console disables credential priming and writes rather than offering edits that would not take effect.

Change storage exists for a deliberate move of platform secrets into Vault or a cloud secret manager. Whatever you pick should stay under platform control; pointing platform storage at a customer-controlled vault mixes two trust boundaries that need to stay apart.

The platform's own storage

Full schema: Secret Management API.

Provider, Shared providers, Tenant policy