Skip to content

Commit fc8ebee

Browse files
committed
docs: omit provider-level PAM parameters from store guides
1 parent 6d701d4 commit fc8ebee

60 files changed

Lines changed: 657 additions & 658 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

docs/use-cases/Certificate Store Operations/Store Types/README.md

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -13,19 +13,19 @@ Use `kfutil stores import generate-template` against a live Command environment
1313

1414
## PAM Provider Parameter Columns
1515

16-
PAM-backed secret columns vary by PAM provider type. Provider-level parameters are configured on the PAM provider. Store CSV rows use the instance-level parameter names with the secret column prefix, for example `Properties.ServerPassword.Parameters.SecretId` or `Password.Parameters.SecretId`.
16+
PAM-backed secret columns vary by PAM provider type. Certificate store CSV rows can only set the instance-level parameter names exposed to certificate stores, with the secret column prefix. For example, use `Properties.ServerPassword.Parameters.SecretId` or `Password.Parameters.SecretId`.
1717

18-
| PAM type | Provider-level parameters | Store CSV instance parameters |
19-
| --- | --- | --- |
20-
| `1Password-CLI` | Vault, Token | Item, Field |
21-
| `Azure-KeyVault` | KeyVaultUri, AuthorityHost | SecretId |
22-
| `Azure-KeyVault-ServicePrincipal` | KeyVaultUri, AuthorityHost, TenantId, ClientId, ClientSecret | SecretId |
23-
| `BeyondTrust-PasswordSafe` | Host, APIKey, Username, ClientCertificate | SystemId, AccountId |
24-
| `CyberArk-CentralCredentialProvider` | AppId, Host, Site | Safe, Folder, Object |
25-
| `CyberArk-SdkCredentialProvider` | AppId | Safe, Folder, Object |
26-
| `Delinea-SecretServer` | Host, Username, Password, ClientId, ClientSecret, GrantType | SecretId, SecretFieldName |
27-
| `GCP-SecretManager` | projectId | secretId |
28-
| `Hashicorp-Vault` | Host, Token, Path | Secret, Key |
18+
| PAM type | Store CSV parameter names |
19+
| --- | --- |
20+
| `1Password-CLI` | Item, Field |
21+
| `Azure-KeyVault` | SecretId |
22+
| `Azure-KeyVault-ServicePrincipal` | SecretId |
23+
| `BeyondTrust-PasswordSafe` | SystemId, AccountId |
24+
| `CyberArk-CentralCredentialProvider` | Safe, Folder, Object |
25+
| `CyberArk-SdkCredentialProvider` | Safe, Folder, Object |
26+
| `Delinea-SecretServer` | SecretId, SecretFieldName |
27+
| `GCP-SecretManager` | secretId |
28+
| `Hashicorp-Vault` | Secret, Key |
2929

3030
## Store Types
3131

docs/use-cases/Certificate Store Operations/Store Types/akamai.md

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -150,17 +150,17 @@ Properties.client_secret.Provider,Properties.client_secret.Parameters.<Parameter
150150

151151
Use the PAM parameter names in the table below, or check the provider type in Command if your environment uses custom PAM types.
152152

153-
| PAM type | Provider-level parameters | Store CSV instance parameters |
154-
| --- | --- | --- |
155-
| `1Password-CLI` | Vault, Token | Item, Field |
156-
| `Azure-KeyVault` | KeyVaultUri, AuthorityHost | SecretId |
157-
| `Azure-KeyVault-ServicePrincipal` | KeyVaultUri, AuthorityHost, TenantId, ClientId, ClientSecret | SecretId |
158-
| `BeyondTrust-PasswordSafe` | Host, APIKey, Username, ClientCertificate | SystemId, AccountId |
159-
| `CyberArk-CentralCredentialProvider` | AppId, Host, Site | Safe, Folder, Object |
160-
| `CyberArk-SdkCredentialProvider` | AppId | Safe, Folder, Object |
161-
| `Delinea-SecretServer` | Host, Username, Password, ClientId, ClientSecret, GrantType | SecretId, SecretFieldName |
162-
| `GCP-SecretManager` | projectId | secretId |
163-
| `Hashicorp-Vault` | Host, Token, Path | Secret, Key |
153+
| PAM type | Store CSV parameter names |
154+
| --- | --- |
155+
| `1Password-CLI` | Item, Field |
156+
| `Azure-KeyVault` | SecretId |
157+
| `Azure-KeyVault-ServicePrincipal` | SecretId |
158+
| `BeyondTrust-PasswordSafe` | SystemId, AccountId |
159+
| `CyberArk-CentralCredentialProvider` | Safe, Folder, Object |
160+
| `CyberArk-SdkCredentialProvider` | Safe, Folder, Object |
161+
| `Delinea-SecretServer` | SecretId, SecretFieldName |
162+
| `GCP-SecretManager` | secretId |
163+
| `Hashicorp-Vault` | Secret, Key |
164164

165165
## References
166166

docs/use-cases/Certificate Store Operations/Store Types/appgwbin.md

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -109,17 +109,17 @@ Properties.ClientCertificate.Provider,Properties.ClientCertificate.Parameters.<P
109109

110110
Use the PAM parameter names in the table below, or check the provider type in Command if your environment uses custom PAM types.
111111

112-
| PAM type | Provider-level parameters | Store CSV instance parameters |
113-
| --- | --- | --- |
114-
| `1Password-CLI` | Vault, Token | Item, Field |
115-
| `Azure-KeyVault` | KeyVaultUri, AuthorityHost | SecretId |
116-
| `Azure-KeyVault-ServicePrincipal` | KeyVaultUri, AuthorityHost, TenantId, ClientId, ClientSecret | SecretId |
117-
| `BeyondTrust-PasswordSafe` | Host, APIKey, Username, ClientCertificate | SystemId, AccountId |
118-
| `CyberArk-CentralCredentialProvider` | AppId, Host, Site | Safe, Folder, Object |
119-
| `CyberArk-SdkCredentialProvider` | AppId | Safe, Folder, Object |
120-
| `Delinea-SecretServer` | Host, Username, Password, ClientId, ClientSecret, GrantType | SecretId, SecretFieldName |
121-
| `GCP-SecretManager` | projectId | secretId |
122-
| `Hashicorp-Vault` | Host, Token, Path | Secret, Key |
112+
| PAM type | Store CSV parameter names |
113+
| --- | --- |
114+
| `1Password-CLI` | Item, Field |
115+
| `Azure-KeyVault` | SecretId |
116+
| `Azure-KeyVault-ServicePrincipal` | SecretId |
117+
| `BeyondTrust-PasswordSafe` | SystemId, AccountId |
118+
| `CyberArk-CentralCredentialProvider` | Safe, Folder, Object |
119+
| `CyberArk-SdkCredentialProvider` | Safe, Folder, Object |
120+
| `Delinea-SecretServer` | SecretId, SecretFieldName |
121+
| `GCP-SecretManager` | secretId |
122+
| `Hashicorp-Vault` | Secret, Key |
123123

124124
## References
125125

docs/use-cases/Certificate Store Operations/Store Types/aruba.md

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -115,17 +115,17 @@ Properties.FileServerPassword.Provider,Properties.FileServerPassword.Parameters.
115115

116116
Use the PAM parameter names in the table below, or check the provider type in Command if your environment uses custom PAM types.
117117

118-
| PAM type | Provider-level parameters | Store CSV instance parameters |
119-
| --- | --- | --- |
120-
| `1Password-CLI` | Vault, Token | Item, Field |
121-
| `Azure-KeyVault` | KeyVaultUri, AuthorityHost | SecretId |
122-
| `Azure-KeyVault-ServicePrincipal` | KeyVaultUri, AuthorityHost, TenantId, ClientId, ClientSecret | SecretId |
123-
| `BeyondTrust-PasswordSafe` | Host, APIKey, Username, ClientCertificate | SystemId, AccountId |
124-
| `CyberArk-CentralCredentialProvider` | AppId, Host, Site | Safe, Folder, Object |
125-
| `CyberArk-SdkCredentialProvider` | AppId | Safe, Folder, Object |
126-
| `Delinea-SecretServer` | Host, Username, Password, ClientId, ClientSecret, GrantType | SecretId, SecretFieldName |
127-
| `GCP-SecretManager` | projectId | secretId |
128-
| `Hashicorp-Vault` | Host, Token, Path | Secret, Key |
118+
| PAM type | Store CSV parameter names |
119+
| --- | --- |
120+
| `1Password-CLI` | Item, Field |
121+
| `Azure-KeyVault` | SecretId |
122+
| `Azure-KeyVault-ServicePrincipal` | SecretId |
123+
| `BeyondTrust-PasswordSafe` | SystemId, AccountId |
124+
| `CyberArk-CentralCredentialProvider` | Safe, Folder, Object |
125+
| `CyberArk-SdkCredentialProvider` | Safe, Folder, Object |
126+
| `Delinea-SecretServer` | SecretId, SecretFieldName |
127+
| `GCP-SecretManager` | secretId |
128+
| `Hashicorp-Vault` | Secret, Key |
129129

130130
## References
131131

docs/use-cases/Certificate Store Operations/Store Types/aws-acm-v3.md

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -126,17 +126,17 @@ Properties.IAMUserAccessSecret.Provider,Properties.IAMUserAccessSecret.Parameter
126126

127127
Use the PAM parameter names in the table below, or check the provider type in Command if your environment uses custom PAM types.
128128

129-
| PAM type | Provider-level parameters | Store CSV instance parameters |
130-
| --- | --- | --- |
131-
| `1Password-CLI` | Vault, Token | Item, Field |
132-
| `Azure-KeyVault` | KeyVaultUri, AuthorityHost | SecretId |
133-
| `Azure-KeyVault-ServicePrincipal` | KeyVaultUri, AuthorityHost, TenantId, ClientId, ClientSecret | SecretId |
134-
| `BeyondTrust-PasswordSafe` | Host, APIKey, Username, ClientCertificate | SystemId, AccountId |
135-
| `CyberArk-CentralCredentialProvider` | AppId, Host, Site | Safe, Folder, Object |
136-
| `CyberArk-SdkCredentialProvider` | AppId | Safe, Folder, Object |
137-
| `Delinea-SecretServer` | Host, Username, Password, ClientId, ClientSecret, GrantType | SecretId, SecretFieldName |
138-
| `GCP-SecretManager` | projectId | secretId |
139-
| `Hashicorp-Vault` | Host, Token, Path | Secret, Key |
129+
| PAM type | Store CSV parameter names |
130+
| --- | --- |
131+
| `1Password-CLI` | Item, Field |
132+
| `Azure-KeyVault` | SecretId |
133+
| `Azure-KeyVault-ServicePrincipal` | SecretId |
134+
| `BeyondTrust-PasswordSafe` | SystemId, AccountId |
135+
| `CyberArk-CentralCredentialProvider` | Safe, Folder, Object |
136+
| `CyberArk-SdkCredentialProvider` | Safe, Folder, Object |
137+
| `Delinea-SecretServer` | SecretId, SecretFieldName |
138+
| `GCP-SecretManager` | secretId |
139+
| `Hashicorp-Vault` | Secret, Key |
140140

141141
## References
142142

docs/use-cases/Certificate Store Operations/Store Types/aws-acm.md

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -123,17 +123,17 @@ Properties.ServerPassword.Provider,Properties.ServerPassword.Parameters.<Paramet
123123

124124
Use the PAM parameter names in the table below, or check the provider type in Command if your environment uses custom PAM types.
125125

126-
| PAM type | Provider-level parameters | Store CSV instance parameters |
127-
| --- | --- | --- |
128-
| `1Password-CLI` | Vault, Token | Item, Field |
129-
| `Azure-KeyVault` | KeyVaultUri, AuthorityHost | SecretId |
130-
| `Azure-KeyVault-ServicePrincipal` | KeyVaultUri, AuthorityHost, TenantId, ClientId, ClientSecret | SecretId |
131-
| `BeyondTrust-PasswordSafe` | Host, APIKey, Username, ClientCertificate | SystemId, AccountId |
132-
| `CyberArk-CentralCredentialProvider` | AppId, Host, Site | Safe, Folder, Object |
133-
| `CyberArk-SdkCredentialProvider` | AppId | Safe, Folder, Object |
134-
| `Delinea-SecretServer` | Host, Username, Password, ClientId, ClientSecret, GrantType | SecretId, SecretFieldName |
135-
| `GCP-SecretManager` | projectId | secretId |
136-
| `Hashicorp-Vault` | Host, Token, Path | Secret, Key |
126+
| PAM type | Store CSV parameter names |
127+
| --- | --- |
128+
| `1Password-CLI` | Item, Field |
129+
| `Azure-KeyVault` | SecretId |
130+
| `Azure-KeyVault-ServicePrincipal` | SecretId |
131+
| `BeyondTrust-PasswordSafe` | SystemId, AccountId |
132+
| `CyberArk-CentralCredentialProvider` | Safe, Folder, Object |
133+
| `CyberArk-SdkCredentialProvider` | Safe, Folder, Object |
134+
| `Delinea-SecretServer` | SecretId, SecretFieldName |
135+
| `GCP-SecretManager` | secretId |
136+
| `Hashicorp-Vault` | Secret, Key |
137137

138138
## References
139139

docs/use-cases/Certificate Store Operations/Store Types/axisipcamera.md

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -113,17 +113,17 @@ Properties.ServerPassword.Provider,Properties.ServerPassword.Parameters.<Paramet
113113

114114
Use the PAM parameter names in the table below, or check the provider type in Command if your environment uses custom PAM types.
115115

116-
| PAM type | Provider-level parameters | Store CSV instance parameters |
117-
| --- | --- | --- |
118-
| `1Password-CLI` | Vault, Token | Item, Field |
119-
| `Azure-KeyVault` | KeyVaultUri, AuthorityHost | SecretId |
120-
| `Azure-KeyVault-ServicePrincipal` | KeyVaultUri, AuthorityHost, TenantId, ClientId, ClientSecret | SecretId |
121-
| `BeyondTrust-PasswordSafe` | Host, APIKey, Username, ClientCertificate | SystemId, AccountId |
122-
| `CyberArk-CentralCredentialProvider` | AppId, Host, Site | Safe, Folder, Object |
123-
| `CyberArk-SdkCredentialProvider` | AppId | Safe, Folder, Object |
124-
| `Delinea-SecretServer` | Host, Username, Password, ClientId, ClientSecret, GrantType | SecretId, SecretFieldName |
125-
| `GCP-SecretManager` | projectId | secretId |
126-
| `Hashicorp-Vault` | Host, Token, Path | Secret, Key |
116+
| PAM type | Store CSV parameter names |
117+
| --- | --- |
118+
| `1Password-CLI` | Item, Field |
119+
| `Azure-KeyVault` | SecretId |
120+
| `Azure-KeyVault-ServicePrincipal` | SecretId |
121+
| `BeyondTrust-PasswordSafe` | SystemId, AccountId |
122+
| `CyberArk-CentralCredentialProvider` | Safe, Folder, Object |
123+
| `CyberArk-SdkCredentialProvider` | Safe, Folder, Object |
124+
| `Delinea-SecretServer` | SecretId, SecretFieldName |
125+
| `GCP-SecretManager` | secretId |
126+
| `Hashicorp-Vault` | Secret, Key |
127127

128128
## References
129129

docs/use-cases/Certificate Store Operations/Store Types/azureapp.md

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -109,17 +109,17 @@ Properties.ClientCertificate.Provider,Properties.ClientCertificate.Parameters.<P
109109

110110
Use the PAM parameter names in the table below, or check the provider type in Command if your environment uses custom PAM types.
111111

112-
| PAM type | Provider-level parameters | Store CSV instance parameters |
113-
| --- | --- | --- |
114-
| `1Password-CLI` | Vault, Token | Item, Field |
115-
| `Azure-KeyVault` | KeyVaultUri, AuthorityHost | SecretId |
116-
| `Azure-KeyVault-ServicePrincipal` | KeyVaultUri, AuthorityHost, TenantId, ClientId, ClientSecret | SecretId |
117-
| `BeyondTrust-PasswordSafe` | Host, APIKey, Username, ClientCertificate | SystemId, AccountId |
118-
| `CyberArk-CentralCredentialProvider` | AppId, Host, Site | Safe, Folder, Object |
119-
| `CyberArk-SdkCredentialProvider` | AppId | Safe, Folder, Object |
120-
| `Delinea-SecretServer` | Host, Username, Password, ClientId, ClientSecret, GrantType | SecretId, SecretFieldName |
121-
| `GCP-SecretManager` | projectId | secretId |
122-
| `Hashicorp-Vault` | Host, Token, Path | Secret, Key |
112+
| PAM type | Store CSV parameter names |
113+
| --- | --- |
114+
| `1Password-CLI` | Item, Field |
115+
| `Azure-KeyVault` | SecretId |
116+
| `Azure-KeyVault-ServicePrincipal` | SecretId |
117+
| `BeyondTrust-PasswordSafe` | SystemId, AccountId |
118+
| `CyberArk-CentralCredentialProvider` | Safe, Folder, Object |
119+
| `CyberArk-SdkCredentialProvider` | Safe, Folder, Object |
120+
| `Delinea-SecretServer` | SecretId, SecretFieldName |
121+
| `GCP-SecretManager` | secretId |
122+
| `Hashicorp-Vault` | Secret, Key |
123123

124124
## References
125125

docs/use-cases/Certificate Store Operations/Store Types/azureapp2.md

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -111,17 +111,17 @@ Properties.ClientCertificatePassword.Provider,Properties.ClientCertificatePasswo
111111

112112
Use the PAM parameter names in the table below, or check the provider type in Command if your environment uses custom PAM types.
113113

114-
| PAM type | Provider-level parameters | Store CSV instance parameters |
115-
| --- | --- | --- |
116-
| `1Password-CLI` | Vault, Token | Item, Field |
117-
| `Azure-KeyVault` | KeyVaultUri, AuthorityHost | SecretId |
118-
| `Azure-KeyVault-ServicePrincipal` | KeyVaultUri, AuthorityHost, TenantId, ClientId, ClientSecret | SecretId |
119-
| `BeyondTrust-PasswordSafe` | Host, APIKey, Username, ClientCertificate | SystemId, AccountId |
120-
| `CyberArk-CentralCredentialProvider` | AppId, Host, Site | Safe, Folder, Object |
121-
| `CyberArk-SdkCredentialProvider` | AppId | Safe, Folder, Object |
122-
| `Delinea-SecretServer` | Host, Username, Password, ClientId, ClientSecret, GrantType | SecretId, SecretFieldName |
123-
| `GCP-SecretManager` | projectId | secretId |
124-
| `Hashicorp-Vault` | Host, Token, Path | Secret, Key |
114+
| PAM type | Store CSV parameter names |
115+
| --- | --- |
116+
| `1Password-CLI` | Item, Field |
117+
| `Azure-KeyVault` | SecretId |
118+
| `Azure-KeyVault-ServicePrincipal` | SecretId |
119+
| `BeyondTrust-PasswordSafe` | SystemId, AccountId |
120+
| `CyberArk-CentralCredentialProvider` | Safe, Folder, Object |
121+
| `CyberArk-SdkCredentialProvider` | Safe, Folder, Object |
122+
| `Delinea-SecretServer` | SecretId, SecretFieldName |
123+
| `GCP-SecretManager` | secretId |
124+
| `Hashicorp-Vault` | Secret, Key |
125125

126126
## References
127127

docs/use-cases/Certificate Store Operations/Store Types/azureappgw.md

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -109,17 +109,17 @@ Properties.ClientCertificate.Provider,Properties.ClientCertificate.Parameters.<P
109109

110110
Use the PAM parameter names in the table below, or check the provider type in Command if your environment uses custom PAM types.
111111

112-
| PAM type | Provider-level parameters | Store CSV instance parameters |
113-
| --- | --- | --- |
114-
| `1Password-CLI` | Vault, Token | Item, Field |
115-
| `Azure-KeyVault` | KeyVaultUri, AuthorityHost | SecretId |
116-
| `Azure-KeyVault-ServicePrincipal` | KeyVaultUri, AuthorityHost, TenantId, ClientId, ClientSecret | SecretId |
117-
| `BeyondTrust-PasswordSafe` | Host, APIKey, Username, ClientCertificate | SystemId, AccountId |
118-
| `CyberArk-CentralCredentialProvider` | AppId, Host, Site | Safe, Folder, Object |
119-
| `CyberArk-SdkCredentialProvider` | AppId | Safe, Folder, Object |
120-
| `Delinea-SecretServer` | Host, Username, Password, ClientId, ClientSecret, GrantType | SecretId, SecretFieldName |
121-
| `GCP-SecretManager` | projectId | secretId |
122-
| `Hashicorp-Vault` | Host, Token, Path | Secret, Key |
112+
| PAM type | Store CSV parameter names |
113+
| --- | --- |
114+
| `1Password-CLI` | Item, Field |
115+
| `Azure-KeyVault` | SecretId |
116+
| `Azure-KeyVault-ServicePrincipal` | SecretId |
117+
| `BeyondTrust-PasswordSafe` | SystemId, AccountId |
118+
| `CyberArk-CentralCredentialProvider` | Safe, Folder, Object |
119+
| `CyberArk-SdkCredentialProvider` | Safe, Folder, Object |
120+
| `Delinea-SecretServer` | SecretId, SecretFieldName |
121+
| `GCP-SecretManager` | secretId |
122+
| `Hashicorp-Vault` | Secret, Key |
123123

124124
## References
125125

0 commit comments

Comments
 (0)