UiPath Documentation
orchestrator
latest
false
Orchestrator user guide

Storing Unattended Robot Credentials in HashiCorp Vault (read only)

How unattended robot passwords are stored using the HashiCorp Vault read-only credential store.

Note:

Before performing the following procedure, make sure you have configured your HashiCorp Vault (read-only) integration.

When storing an unattended robot password in a read-only credential store that uses the KeyValueV1 or KeyValueV2 secrets engine, you must create the secret in Vault and make sure you meet the following requirements:

  • the path of the secret must contain the data path configured for the credential store, concatenated with the External Name configured for that robot. For example, if the data path is applications/orchestrator/robots, and the External Name is robot01, then the secret's path must be applications/orchestrator/robots/robot01.
  • inside the secret, you must have a key named Value, and the value must be this robot's password.

With the ActiveDirectory, OpenLDAP, and LDAP engines, you do not provision key-value secrets. Orchestrator asks the engine for the credential by role name and reads the password from the engine's own response, so the Value key does not apply. Leave Data Path empty and set the robot account's External Name to the Vault role name. For the resolved paths, see HashiCorp Vault secret path resolution.

Was this page helpful?

Connect

Need help? Support

Want to learn? UiPath Academy

Have questions? UiPath Forum

Stay updated