Vault configuration

Capability

Support

Comment

Retrieve password as string

Supported feature

Access a stored password as a String for general-purpose use in APIs requiring textual input. See Access passwords from vault.

Retrieve password as byte array

Supported feature

Access a stored password as a byte[], useful for cryptographic libraries or APIs requiring raw binary credentials. See Access passwords from vault.

Retrieve password as char array

Supported feature

Access a stored password as a char[], suitable when minimizing memory exposure time (e.g., for secure handling in Java). See Access passwords from vault.

Centralized password retrieval

Supported feature

Passwords are retrieved from a centralized vault using keys, reducing hardcoded secrets in scripts or modules. See Vault configuration files.

Support multiple vault configuration files

Supported feature

Allows the system to load and merge several vault.ospp files, enabling modular and context-specific password definitions. See Vault configuration files.

Use of password configuration for each password

Supported feature

Using password configuration for each individual password provides the following benefits. See Password configuration and storage.

Context

The vault configuration provides a centralized and modular mechanism to manage sensitive credentials across multiple modules or environments. Instead of hardcoding passwords directly into scripts or configuration files, passwords are defined and retrieved using dedicated Password configuration and storage instances mapped by keys. This approach improves security, promotes separation of concerns, and enhances maintainability by enabling dynamic and context-aware secret management.

Access passwords from vault

Concept

The vault is a centralized key-value store designed to provide secure and structured access to passwords and other sensitive information. Instead of embedding secrets directly into configuration files or scripts, values are accessed dynamically at runtime using a key. These keys are resolved via Password configuration and storage interfaces that abstract the underlying password source.

Each password can be retrieved in multiple formats depending on the target use case:

  • String: for standard APIs or protocols that expect textual credentials.

  • byte[]: for binary-safe interactions, especially cryptographic operations.

  • char[]: for use cases where memory sanitization is required after password usage.

This design minimizes the surface of exposure for sensitive data and avoids the propagation of hardcoded secrets across the system.

Usage

A password can be retrieved in a script using the vault controller exposed by osp-scripts:

let pwd = vault.getPassword("my-key");
let binaryPwd = vault.getBytePassword("crypto-key");
let securePwd = vault.getCharPassword("internal-admin-password");

This provides full flexibility depending on the nature of the downstream component consuming the password.

Example

See Vault Configuration

Vault configuration files

Concept

The system supports multiple vault.ospp files distributed across modules or environments. These configuration files define the available password keys and their associated Password configuration and storage logic.

When multiple vault.ospp files are present, the system merges them into a single logical configuration. All declared keys are treated as if defined in one unified file.

Warning

If the same key is defined in multiple files, the configuration is considered invalid and will lead to an error. It is the user’s responsibility to ensure key uniqueness across all vault.ospp files.

Usage

Each vault.ospp file must define a mapping of keys to password providers:

{
    "moduleId": [
        "modules.scripts.scripts-1"
    ],
    "passwords": [
        {
            "key": "SDN",
            "password": {
                "type": "PLAINTEXT",
                "password": "secret-password"
            }
        }
    ]
}

These files are automatically discovered and aggregated by the configuration dispatcher during startup.

Example

See Vault Configuration