SpecsModelExploreRequirements
SpecsModelExploreRequirements
Secret Store
Overview
Guide
Schema
Twin streams
Links and Communications
IDproduct.platform.secrets_manager.secret_store
DescriptionStores service secrets with KMS encryption.
Keysecret_store
Typecomponent:database
Statusactive
TeamPlatform Engineering
Owner
platform@iotgateway.example
TechnologiesHashiCorp Vault, PostgreSQL
Tags
Table of contents
Guide
Secret Store
Data model
Notes
Schema
Links and Communications
Requirements

Attributes

cipherAES-256-GCM
rotation90d

Guide

Secret Store

The Secret Store is the durable, encrypted home for every secret the Secrets Manager issues or holds. It keeps each secret versioned, tracks who has leased it, and enforces which paths a caller may read via policies.

Storage profile

HashiCorp Vault fronts the secret engine; PostgreSQL is the durable backing store. Values are encrypted at rest with AES-256-GCM and never written to logs. Secrets rotate every 90d.

Data model

The schema is small and audit-oriented — secrets, their versions, outstanding leases and the policies that govern access. The ERD is embedded on the Overview tab.

Notes

  • SECRET.path is unique and is the lookup key callers use on GET /secrets/{path}.
  • A secret can have many SECRET_VERSION rows; exactly one is in the active state at a time, older versions stay readable until leases expire.
  • LEASE rows give every read a TTL so a leaked secret has a bounded blast radius — expiry forces a re-fetch through the Secrets Manager API.
  • POLICY.path_glob maps a caller to the secret paths and capabilities it is allowed.

Schema

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.
100%

Links and Communications

1 outgoing link

Outgoing Links(1)

Target objectLabelLink typeRelationRaw idRequiredDescription
CA Service

example-iot.product.platform.secrets_manager.ca_service

component
stores secrets for—linksproduct.platform.secrets_manager.ca_service——

Requirements