access_token_manager_idstring
admin_rotation_interval_daysinteger
administrative_portstring
artifactory_admin_apikeystring
artifactory_admin_usernamestring
artifactory_base_urlstring
artifactory_token_audiencestring
artifactory_token_scopestring
aws_secret_access_keystring
aws_transitive_tag_keysstring
aws_user_console_accessboolean
aws_user_programmatic_accessboolean
azure_administrative_unitstring
azure_app_object_idstring
azure_client_secretstring
azure_fixed_user_name_sub_claim_keystring
azure_fixed_user_onlyboolean
azure_resource_group_namestring
azure_resource_namestring
azure_subscription_idstring
azure_user_groups_obj_idstring
azure_user_portal_accessboolean
azure_user_programmatic_accessboolean
azure_user_roles_template_idstring
cassandra_creation_statementsstring
chef_server_access_modestring
chef_server_host_namestring
chef_server_usernamestring
client_authentication_typestring
client_certificatestring
(Optional) ClientCertificate defines the client certificate for mutual TLS. Must be base64 certificate loaded by UI using file loader field
client_key_passphrasestring
(Optional) ClientKeyPassphrase defines the passphrase for the client private key
client_private_keystring
(Optional) ClientPrivateKey defines the client private key for mutual TLS. Must be base64 private key loaded by UI using file loader field
cloud_service_providerstring
db_private_keystring
(Optional) Private Key in PEM format
db_private_key_passphrasestring
db_server_certificatesstring
(Optional) DBServerCertificates defines the set of root certificate authorities
that clients use when verifying server certificates.
If DBServerCertificates is empty, TLS uses the host's root CA set.
db_server_namestring
(Optional) ServerName is used to verify the hostname on the returned
certificates unless InsecureSkipVerify is given. It is also included
in the client's handshake to support virtual hosting unless it is
an IP address.
dynamic_secret_namestring
dynamic_secret_typestring
eks_cluster_ca_certificatestring
eks_cluster_endpointstring
eks_secret_access_keystring
enable_admin_rotationboolean
enable_mtlsboolean
(Optional) EnableMTLS defines if mutual TLS will be used to connect to DB
enforce_replay_preventionboolean
relevant for PRIVATE_KEY_JWT client authentication type
expiration_datestring date-time
externally_provided_userstring
gcp_fixed_user_claim_keynamestring
gcp_service_account_emailstring
GCPServiceAccountEmail overrides the deprecated field from the target
gcp_service_account_keystring
gcp_service_account_key_base64string
gcp_service_account_key_idstring
gcp_service_account_typestring
gcp_tmp_service_account_namestring
github_app_private_keystring
github_installation_idinteger
github_installation_token_permissionsobject
github_installation_token_repositoriesstring[]
github_installation_token_repositories_idsinteger[]
github_organization_namestring
github_repository_pathstring
gitlab_access_tokenstring
gitlab_project_namestring
gitlab_token_scopestring[]
gke_cluster_ca_certificatestring
gke_cluster_endpointstring
gke_service_account_keystring
gke_service_account_namestring
google_workspace_access_modestring
google_workspace_admin_namestring
google_workspace_fixed_user_name_sub_claim_keystring
google_workspace_group_namestring
google_workspace_group_rolestring
google_workspace_role_namestring
google_workspace_role_scopestring
grace_rotated_secret_keystring
hanadb_creation_statementsstring
hanadb_revocation_statementsstring
implementation_typestring
issuerstring
relevant for CLIENT_TLS_CERTIFICATE client authentication type
k8s_allowed_namespacesstring
comma-separated list of allowed namespaces. Can hold just * which signifies that any namespace is allowed
k8s_client_cert_datastring
For K8s Client certificates authentication
k8s_client_key_datastring
k8s_cluster_ca_certificatestring
k8s_cluster_endpointstring
k8s_dynamic_modeboolean
when native k8s is in dynamic mode, user can define allowed namespaces,
K8sServiceAccount doesn't exist from the start and will only be created at time of getting dynamic secret value
By default dynamic mode is false and producer behaves like it did before
k8s_multiple_doc_yaml_temp_definitioninteger[]
Yaml definition for creation of temporary objects. Field that can hold multiple docs from which following will be extracted:
ServiceAccount, Role/ClusterRole and RoleBinding/ClusterRoleBinding. If ServiceAccount not specified - it will be generated automatically
k8s_role_namestring
Name of the pre-existing Role or ClusterRole to bind a generated service account to.
k8s_service_accountstring
last_admin_rotationinteger
ldap_fixed_user_name_sub_claim_keystring
ldap_fixed_user_typestring
ldap_token_expirationstring
mongodb_atlas_api_private_keystring
mongodb_atlas_api_public_keystring
mongodb_atlas_project_idstring
mongodb_custom_datastring
mongodb_default_auth_dbstring
mongodb_uri_connectionstring
mongodb_uri_optionsstring
mssql_allowed_db_namesstring
Comma-separated list of allowed DB names for runtime selection when fetching the secret value.
Empty string => use target DB name only (no override allowed)
"*" => any DB name is allowed
One or more names => user must select one of the provided names
mssql_creation_statementsstring
mssql_revocation_statementsstring
mysql_creation_statementsstring
mysql_revocation_statementsstring
oracle_creation_statementsstring
oracle_revocation_statementsstring
postgres_creation_statementsstring
postgres_revocation_statementsstring
rabbitmq_server_passwordstring
rabbitmq_server_uristring
rabbitmq_server_userstring
rabbitmq_user_conf_permissionstring
rabbitmq_user_read_permissionstring
rabbitmq_user_vhoststring
rabbitmq_user_write_permissionstring
rdp_fixed_user_name_sub_claim_keystring
redshift_creation_statementsstring
restricted_scopesstring[]
session_extension_warn_interval_mininteger
should_stopstring
TODO delete this after migration
ssl_connection_certificatestring
(Optional) SSLConnectionCertificate defines the certificate for SSL connection. Must be base64 certificate loaded by UI using file loader field
ssl_connection_modeboolean
(Optional) SSLConnectionMode defines if SSL mode will be used to connect to DB
use_gw_cloud_identityboolean
use_gw_service_accountboolean
user_principal_namestring
venafi_allow_subdomainsboolean
venafi_allowed_domainsstring[]
venafi_auto_generated_folderstring
venafi_root_first_in_chainboolean
venafi_sign_using_akeyless_pkiboolean
venafi_signer_key_namestring
venafi_store_private_keyboolean
venafi_tpp_access_tokenstring
venafi_tpp_client_idstring
venafi_tpp_passwordstring
Deprecated: VenafiAccessToken and VenafiRefreshToken should be used instead
venafi_tpp_refresh_tokenstring
venafi_tpp_usernamestring
Deprecated: VenafiAccessToken and VenafiRefreshToken should be used instead
warn_before_user_expiration_mininteger