This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

How-to guides

The user can enter the required information for the Secrets Manager service through the Samsung Cloud Platform Console, select detailed options, and create the service.

Secrets Manager Create

You can create and use Secrets Manager from the Samsung Cloud Platform Console.

To create Secrets Manager, follow the steps below.

  1. All Services > Security > Secrets Manager Click the menu. Navigate to the Service Home page of Secrets Manager.

  2. Click the Secrets Manager Create button on the Service Home page. You will be taken to the Secrets Manager Create page.

  3. Secrets Manager creation On the page, enter the information required to create the service and enter additional information.

    • Service Information Input area, please enter or select the required information.
      Category
      Required status
      Detailed description
      Secret nameRequiredEnter Secret name
      TypeRequiredSelect the type to manage encrypted with Secret from the list
      Key/Value inputRequiredEnter the Secret information’s Key/Value as a pair
      • + Click the + icon to add up to 10
      • X Click the X icon to delete the entry
      Encryption KeyRequiredSelect the KMS key to use when encrypting the Secret from the list
      • Choose a key created in the KMS service from the list. Or click +Create New to create a KMS key
      • Only KMS keys for encryption/decryption can be selected. The selectable encryption/decryption KMS key types are encryption/decryption (AES-256), encryption/decryption and signing/verification (RSA-2048), encryption/decryption (ARIA) – three types
      • When entering Key/Value, input must be within 64 KB; registration is not allowed if the size exceeds
      • For detailed information on creating a KMS key, refer to Create KMS Key
      Public Access ControlRequiredEnter public access allowed IP
      • After entering IP address, click Add button to register up to 10
      • Click Delete All button to delete all IP entries in the list
      • 0.0.0.0/24 - 0.0.0.0/32 ranges can be registered but may be vulnerable to security
      Private Access ControlSelectUse After selecting, select resources to allow private access
      • Click the Add button to add an access-allowed resource
      • If not set to use, all subnet resources in the same region are allowed access
      DescriptionSelectEnter description for Secrets Manager
      Table. Secrets Manager service information input items
    • Additional Information Input Enter or select the required information in the area.
      Category
      Required or not
      Detailed description
      TagSelectAdd Tag
      • Up to 50 can be added per resource
      • After clicking the Add Tag button, enter or select Key, Value values
      Table. Secrets Manager additional information input items
  4. Summary Check the detailed information and estimated billing amount generated in the panel, and click the Create button.

    • When creation is complete, check the created resource on the Secrets Manager List page.

Secrets Manager View Detailed Information

Secrets Manager can view and edit the full list of resources and detailed information. Secrets Manager Details page consists of Detailed Information, Version, Tag, Activity History tabs.

To view detailed information of Secrets Manager, follow the steps below.

  1. All Services > Security > Secrets Manager Click the menu. Go to the Service Home page of Secrets Manager.
  2. Click the Secrets Manager menu on the Service Home page. You will be taken to the Secrets Manager List page.
  3. Secrets Manager List Click the resource to view detailed information on the page. Go to the Secrets Manager Details page.
  • Secrets Manager Details At the top of the page, status information and descriptions of additional features are displayed.
    CategoryDetailed description
    StatusDisplays the status of Secrets Manager
    • Active: available/active
    • To be terminated: scheduled for deletion
    Service cancellationButton to cancel the service
    Table. Secrets Manager status information and additional features

Detailed Information

Secrets Manager List page allows you to view detailed information of the selected resource and, if necessary, edit the information.

Category
Detailed description
serviceservice name
Resource TypeResource Type
SRNUnique resource ID in Samsung Cloud Platform
Resource NameResource Name
Resource IDUnique resource ID in the service
CreatorUser who created the service
Creation timeService creation time
EditorUser who modified the service
Modification Date and TimeService Modification Date and Time
Secret nameName of the created Secret
Secret valueEntered Secret value
  • View button click then after entering password, you can view and edit information in the Secret value view window
TypeType of the generated Secret
Recent search date/timeRecent search date/time of generated Secret
Encryption KeyDisplays the KMS key name selected by the user
  • Clicking the key name navigates to the KMS key detail page
  • Clicking the edit icon allows changing the key in the encryption key edit window
URLPublic/Private URL information display
  • Copy icon can be clicked to copy the URL address
Public Access ControlDisplay registered public access allowed IP
  • Edit icon can be clicked to modify IP address
Private Access ControlDisplay registered private access allowed resources
  • Edit icon click enables resource modification
DescriptionDisplay additional description for Secret
  • Click the edit icon to edit the description
Table. Secrets Manager detailed information tab items

Version

Secrets Manager List page allows you to track the version of a selected Secret using labels.

Reference

When checking the version information of Secret Manager, refer to the definition of each item.

  • Secret: Logical unit that stores sensitive (important) information
  • Version: a snapshot of unique data that is newly created each time the Secret is modified (the unit that stores the actual value of the Secret)
  • Label: a name tag or label attached to a specific version of a Secret (a pointer to reference a specific version)
CategoryDetailed description
Version IDDisplays the ID of the current version, previous version, and the version with a custom label (Custom Label) set
  • Copy Click the icon to copy the version ID value
LabelSecret version display
  • CURRENT: current version
  • PREVIOUS: previous version
  • CUSTOM_LABEL: custom label
Last Access TimeSecret’s Recent Access Time
Creation timeCreation time of Secret
Table. Secrets Manager version tab items
Caution

The constraints when using Secret’s version are as follows.

  • Up to 100 versions can be stored per Secret. Regardless of whether a custom label is set, if the number of versions exceeds 100, the oldest versions will be deleted.
  • For important versions with custom labels set, create a new Secret before the version is deleted due to quota exceedance, and configure the running application to reference the new Secret.

Tag

On the Secrets Manager List page, you can view the tag information of the selected resource, and you can add, modify, or delete it.

CategoryDetailed description
Tag ListTag List
  • You can check the tag’s Key, Value information
  • Up to 50 tags can be added per resource
  • When entering a tag, search and select from the existing Key and Value list
Table. Secrets Manager tag tab items

Work History

Secrets Manager list page allows you to view the operation history of the selected resource.

CategoryDetailed description
Work DetailsWork Execution Content
Work date and timeTask execution date and time
Resource TypeResource Type
Resource NameResource Name
Work resultTask execution result (success/failure)
Operator InformationInformation of the user who performed the task
Table. Secrets Manager operation history tab detailed information items

Secrets Manager Cancel

You can cancel the unused Secrets Manager.

Caution
If you cancel Secret Manager, you cannot use any features of Secrets Manager, and it will be permanently deleted after the cancellation waiting period. During the cancellation waiting period, the Secret cannot be searched.

To cancel Secrets Manager, follow the steps below.

  1. All Services > Security > Secrets Manager Click the menu. Navigate to the Service Home page of Secrets Manager.
  2. Click the Secrets Manager menu on the Service Home page. Go to the Secrets Manager List page.
  3. Secrets Manager List page, click the resource to view detailed information. You will be taken to the Secrets Manager Details page.
  4. Secrets Manager Details on the page, click the Cancel Service button. You will be taken to the Cancel Service popup.
  5. Service Termination popup window, enter the cancellation waiting period and click the Confirm button.
    • The termination waiting period can be entered within the range of 7 - 30 days.
  6. Once termination is complete, check on the Secrets Manager list page whether the resource has been terminated.
Guide
If you want to reuse the Secret during the termination waiting period, go to the Secrets Manager List page and click the context menu of the desired Secret item > Cancel termination. If the termination cancellation succeeds, you can use the Secret again.

1 - Secret lookup API reference

This user guide explains how to use and call the Public / Private Endpoint of Secrets Manager.

Caution
  • Public Endpoint can be called in an environment where internet communication is possible.
  • Private Endpoint can only be called from Samsung Cloud Platform VMs.

Pre-setup for Endpoint call

Describes the prerequisite configuration items required when calling the Secrets Manager endpoint.

Register Security Group’s Outbound Rule

To call the endpoint, you need to register an outbound rule in the security group.

To register the Outbound Rule of the Security Group, follow the steps below.

  1. Click the All Services > Security > Secrets Manager menu. Navigate to the Service Home page of Secrets Manager.
  2. Click the Secrets Manager menu on the Service Home page. Navigate to the Secrets Manager List page.
  3. On the Secrets Manager List page, click the resource to view detailed information. You will be taken to the Secrets Manager Details page.
  4. Check the URL information on the Secrets Manager Details page.
    • URL You can copy the public / private URL information from the URL item.
  5. Use the nslookup command to check the IP to register in the Security Group.
nslookup <endpoint URL to call>
  1. Security Group > Security Group List: Select the Security Group of the VM for which you want to set access control. Security Group Details page will be opened.
  2. In the Security Group Details > Rules tab, click the Add Rule button. When the Add Rule window appears, enter the information below to add a rule.
    ItemDetailed description
    Target Input MethodCIDR Select
    Target addressEnter the IP address retrieved by nslookup
    TypeSelect Destination Port/Type after entering protocol information
    • Among protocols TCP select, enter 443 in TCP destination port
    DirectionOutbound rule Select
    DescriptionEnter Secrets Manager Public / Private Endpoint call rule
    Table. Security Group rule addition input items
  3. Security Group rules Check that the rule you entered in the list has been added.

Register access control for Secrets Manager

You can register public/private access controls for Secrets Manager.

To configure the access control items of Secrets Manager, follow the steps below.

  1. Click the All Services > Security > Secrets Manager menu. Go to the Service Home page of Secrets Manager.
  2. Service Home page, click the Secrets Manager menu. Navigate to the Secrets Manager list page.
  3. Secrets Manager list On the page, click the resource to view detailed information. Secrets Manager detail You will be taken to the page.
  4. On the Secrets Manager Details page, click the edit icon of Public Access Control to add an allowed IP for Public Endpoint access.
  • Public Access Control Edit Popup In the window, enter the IP and click the Add button. When addition is complete, click the Confirm button.
    • For security, adding a single IP is recommended, and up to 10 can be registered.
    • 0.0.0.0/24 - 0.0.0.0/32 can be registered, but be careful as it may be insecure.
  1. On the Secrets Manager Details page, click the edit icon of Private Access Control to add a VM that allows Private Endpoint access.
    • In the Private Access Control Edit Popup window, select the resources to allow access and click the Add button. When the addition is complete, click the Confirm button.
    • If you do not set usage, you can access all subnet resources in the same region.

Secrets Manager API Call

Explains how to call the Secrets Manager API.

Check Secrets Manager URL information

All Services > Security > Secrets Manager > Secrets Manager Details page, check the URL information.

  • URL You can copy public / private URL information from the item.

Secrets Manager Lookup API

get /v1/secret

## Description

Secret value lookup

## Parameters





Type Name Description Schema
query secretId (required) Secret ID
(Example : b3ed8b7637574255b83c274a6ed79426)
string
Table. API Call Parameters Item
## Responses
Http Code Description Schema
200 OK None
400 Bad Request None
401 Unauthorized None
403 IP Not Allowed None
404 Not Found None
Table. API call Responses items
## Example HTTP request ### Request path

/v1/secret?secretId={secretId}

### Request header

“Accesskey = 2sd2gg=2agbdSD26svcD”, SecretKey = fsfsdf235f9U35sdgf35Xsf/qgsdgsdg326=sfsdr23rsef=


## Example HTTP response

### Response 200

{ “status”: “success”, “data”: { “key”: “value” }, “timestamp”: “2026-01-20T09:21:18.92730172” “}