Vault configuration
Capability |
Support |
Comment |
|---|---|---|
Retrieve password as string |
Access a stored password as a String for general-purpose use in APIs requiring textual input. See Access passwords from vault. |
|
Retrieve password as byte array |
Access a stored password as a byte[], useful for cryptographic libraries or APIs requiring raw binary credentials. See Access passwords from vault. |
|
Retrieve password as char array |
Access a stored password as a char[], suitable when minimizing memory exposure time (e.g., for secure handling in Java). See Access passwords from vault. |
|
Centralized password retrieval |
Passwords are retrieved from a centralized vault using keys, reducing hardcoded secrets in scripts or modules. See Vault configuration files. |
|
Support multiple vault configuration files |
Allows the system to load and merge several vault.ospp files, enabling modular and context-specific password definitions. See Vault configuration files. |
|
Use of password configuration for each password |
Using password configuration for each individual password provides the following benefits. See Password configuration and storage. |
Context
The vault configuration provides a centralized and modular mechanism to manage sensitive credentials across multiple modules or environments. Instead of hardcoding passwords directly into scripts or configuration files, passwords are defined and retrieved using dedicated Password configuration and storage instances mapped by keys. This approach improves security, promotes separation of concerns, and enhances maintainability by enabling dynamic and context-aware secret management.
Access passwords from vault
Concept
The vault is a centralized key-value store designed to provide secure and structured access to passwords and other sensitive information. Instead of embedding secrets directly into configuration files or scripts, values are accessed dynamically at runtime using a key. These keys are resolved via Password configuration and storage interfaces that abstract the underlying password source.
Each password can be retrieved in multiple formats depending on the target use case:
String: for standard APIs or protocols that expect textual credentials.
byte[]: for binary-safe interactions, especially cryptographic operations.
char[]: for use cases where memory sanitization is required after password usage.
This design minimizes the surface of exposure for sensitive data and avoids the propagation of hardcoded secrets across the system.
Usage
A password can be retrieved in a script using the vault controller exposed by osp-scripts:
let pwd = vault.getPassword("my-key");
let binaryPwd = vault.getBytePassword("crypto-key");
let securePwd = vault.getCharPassword("internal-admin-password");
This provides full flexibility depending on the nature of the downstream component consuming the password.
Example
Vault configuration files
Concept
The system supports multiple vault.ospp files distributed across modules or environments. These configuration files define the available password keys and their associated Password configuration and storage logic.
When multiple vault.ospp files are present, the system merges them into a single logical configuration. All declared keys are treated as if defined in one unified file.
Warning
If the same key is defined in multiple files, the configuration is considered invalid and will lead to an error. It is the user’s responsibility to ensure key uniqueness across all vault.ospp files.
Usage
Each vault.ospp file must define a mapping of keys to password providers:
{
"moduleId": [
"modules.scripts.scripts-1"
],
"passwords": [
{
"key": "SDN",
"password": {
"type": "PLAINTEXT",
"password": "secret-password"
}
}
]
}
These files are automatically discovered and aggregated by the configuration dispatcher during startup.