- Getting started
- Best practices
- Tenant
- About the Tenant Context
- Searching for Resources in a Tenant
- Managing Robots
- Connecting Robots to Orchestrator
- Storing Robot Credentials in CyberArk
- Storing Unattended Robot Passwords in Azure Key Vault (read only)
- Storing Unattended Robot Credentials in HashiCorp Vault (read only)
- Storing Unattended Robot Credentials in AWS Secrets Manager (read only)
- Deleting Disconnected and Unresponsive Unattended Sessions
- Robot Authentication
- Robot Authentication With Client Credentials
- Configuring automation capabilities
- Solutions
- Audit
- Settings
- Registry
- Notifications
- Folders Context
- Processes
- Jobs
- Apps
- Triggers
- Logs
- Monitoring
- Indexes
- Queues
- Assets
- Connections
- Business Rules
- Storage Buckets
- Agent Gateway
- Orchestrator testing
- Resource Catalog Service
- Integrations
- Troubleshooting
Storing Unattended Robot Credentials in HashiCorp Vault (read only)
How unattended robot passwords are stored using the HashiCorp Vault read-only credential store.
Before performing the following procedure, make sure you have configured your HashiCorp Vault (read-only) integration.
When storing an unattended robot password in a read-only credential store that uses the KeyValueV1 or KeyValueV2 secrets engine, you must create the secret in Vault and make sure you meet the following requirements:
- the path of the secret must contain the data path configured for the credential store, concatenated with the External Name configured for that robot. For example, if the data path is
applications/orchestrator/robots, and the External Name isrobot01, then the secret's path must beapplications/orchestrator/robots/robot01. - inside the secret, you must have a key named
Value, and the value must be this robot's password.
With the ActiveDirectory, OpenLDAP, and LDAP engines, you do not provision key-value secrets. Orchestrator asks the engine for the credential by role name and reads the password from the engine's own response, so the Value key does not apply. Leave Data Path empty and set the robot account's External Name to the Vault role name. For the resolved paths, see HashiCorp Vault secret path resolution.