Vault Configuration
This tutorial demonstrates how to create a script that leverages the Vault configuration functionality to retrieve data securely from the vault.
Declare a vault in
vault.osppcontaining secret entries identified by key.Create a variable with
owner.variablesto store the retrieved secret at runtime.Write a detached JS script that reads a vault entry by key and writes it to the variable every 10 seconds.
Verify the retrieved value in the variable or in the script logs.
git checkout origin/osp-scripts-configuration .
git checkout origin/osp-variables-configuration .
git checkout origin/example-scripts-vault-usage .
Steps
1. Create a vault
root/vault/vault.ospp
{
"moduleId": [
"modules.scripts.scripts-1"
],
"passwords": [
{
"key": "SDN",
"password": {
"type": "PLAINTEXT",
"password": "secret-password"
}
}
]
}
This file defines the vault and contains all secret entries.
In this example, a single password is stored under the key SDN.
2. Create a value to store the password
root/values/plaintext/value.ospp
{
"name": "plaintext_value",
"description": "A plaintext value",
"type": "TEXT"
}
root/values/plaintext/owner.variables
{
"moduleId": "modules.variables.variables-1"
}
These files define the plaintext value that will hold the retrieved password. The value is declared as a value.ospp, and ownership is specified in the corresponding owner.variables.
3. Create a script to retrieve the password every 10 seconds
root/script/script.js
let swissdotnet_password = vault.getPassword("SDN");
console.log("PLAINTEXT: " + swissdotnet_password);
values.update("root.values.plaintext", swissdotnet_password);
// getBytePassword
let swissdotnet_byte_password = vault.getBytePassword("SDN");
// getCharPassword
let swissdotnet_char_password = vault.getCharPassword("SDN");
root/script/detached.scripts
{
"moduleId" : "modules.scripts.scripts-1",
"sourceFile" : "root/script/script.js",
"accessedValues" : [],
"scheduledExecutions" : ["0/10 * * ? * * *"]
}
This script periodically retrieves the password from the vault and stores it in the plaintext value.
4. Observe the result
The script logs the password to the console every 10 seconds.
The password can also be viewed in the plaintext value.