- Getting started
- Best practices
- Tenant
- About the Tenant Context
- Searching for Resources in a Tenant
- Managing Robots
- Connecting Robots to Orchestrator
- Storing Robot Credentials in CyberArk
- Storing Unattended Robot Passwords in Azure Key Vault (read only)
- Storing Unattended Robot Credentials in HashiCorp Vault (read only)
- Storing Unattended Robot Credentials in AWS Secrets Manager (read only)
- Deleting Disconnected and Unresponsive Unattended Sessions
- Robot Authentication
- Robot Authentication With Client Credentials
- Configuring automation capabilities
- Solutions
- Audit
- Settings
- Registry
- Notifications
- Folders Context
- Processes
- Jobs
- Apps
- Triggers
- Logs
- Monitoring
- Indexes
- Queues
- Assets
- Connections
- Business Rules
- Storage Buckets
- Agent Gateway
- Orchestrator testing
- Resource Catalog Service
- Integrations
- Troubleshooting
Storing Assets in HashiCorp Vault (read only)
How HashiCorp Vault read-only integration stores Credential and Secret asset types in Orchestrator.
Before performing the following procedure, make sure you have configured your HashiCorp Vault (read-only) integration.
When storing an asset of type Credential or Secret in a read-only credential store that uses the KeyValueV1 or KeyValueV2 secrets engine, you must create the secret in Vault and make sure you meet the following requirements:
- The path of the secret must contain the data path configured for the credential store, concatenated with the External Name configured for that value (if using values per robot) or the asset name otherwise. For example, if the data path is
applications/orchestrator/assets, and the External Name isSAPCredentials, then the secret's path must beapplications/orchestrator/assets/SAPCredentials. - The secret must include the following keys:
- For
Credential-type assets:- a key named
Username, whose value contains the username of the credentials. - a key named
Password, whose value contains the password of the credentials.
- a key named
- For
Secret-type assets:- a key named
Username, whose value contains the asset name. - a key named
Password, whose value contains the value of the secret.
- a key named
- For
The Username and Password fields are case sensitive.
With the ActiveDirectory, OpenLDAP, and LDAP engines, you do not provision key-value secrets. Orchestrator asks the engine for the credential by role name and reads the username and password from the engine's own response, so the Username and Password keys do not apply. Leave Data Path empty and set the asset value's External Name to the Vault role name. For the resolved paths, see HashiCorp Vault secret path resolution.