Vault Configuration

🟢 Beginner

script

This tutorial demonstrates how to create a script that leverages the Vault configuration functionality to retrieve data securely from the vault.

  • Declare a vault in vault.ospp containing secret entries identified by key.

  • Create a variable with owner.variables to store the retrieved secret at runtime.

  • Write a detached JS script that reads a vault entry by key and writes it to the variable every 10 seconds.

  • Verify the retrieved value in the variable or in the script logs.

git checkout origin/osp-scripts-configuration .
git checkout origin/osp-variables-configuration .
git checkout origin/example-scripts-vault-usage .

Steps

1. Create a vault

root/vault/vault.ospp

{
    "moduleId": [
        "modules.scripts.scripts-1"
    ],
    "passwords": [
        {
            "key": "SDN",
            "password": {
                "type": "PLAINTEXT",
                "password": "secret-password"
            }
        }
    ]
}

This file defines the vault and contains all secret entries. In this example, a single password is stored under the key SDN.

2. Create a value to store the password

root/values/plaintext/value.ospp

{
    "name": "plaintext_value",
    "description": "A plaintext value",
    "type": "TEXT"
}

root/values/plaintext/owner.variables

{
    "moduleId": "modules.variables.variables-1"
}

These files define the plaintext value that will hold the retrieved password. The value is declared as a value.ospp, and ownership is specified in the corresponding owner.variables.

3. Create a script to retrieve the password every 10 seconds

root/script/script.js

let swissdotnet_password = vault.getPassword("SDN");

console.log("PLAINTEXT: " + swissdotnet_password);

values.update("root.values.plaintext", swissdotnet_password);

// getBytePassword
let swissdotnet_byte_password = vault.getBytePassword("SDN");

// getCharPassword
let swissdotnet_char_password = vault.getCharPassword("SDN");

root/script/detached.scripts

{
    "moduleId" : "modules.scripts.scripts-1",
    "sourceFile" : "root/script/script.js",
    "accessedValues" : [],
    "scheduledExecutions" : ["0/10 * * ? * * *"]
}

This script periodically retrieves the password from the vault and stores it in the plaintext value.

4. Observe the result

The script logs the password to the console every 10 seconds. The password can also be viewed in the plaintext value.