Skip to main content

okustera_secret (Resource)

The okustera_secret resource securely stores, manages, and rotates sensitive credentials, certificates, passphrases, and encryption keys in OpenStack Barbican.

Example Usage​

Storing Sensitive API Tokens or Passwords​

resource "okustera_secret" "database_creds" {
name = "db-superadmin-password"
payload = var.db_master_password
secret_type = "passphrase"
}

output "secret_ref" {
value = okustera_secret.database_creds.secret_ref
}

Schema​

Required​

  • name (String) Secret name or label.
  • payload (String, Sensitive) Plaintext secret content to encrypt and store.

Optional​

  • secret_type (String) Secret category: passphrase, opaque, certificate, or symmetric. Defaults to passphrase.

Read-Only Attributes​

  • id (String) Secret UUID.
  • secret_ref (String) Canonical Barbican secret reference URI.
  • status (String) Secret status (e.g. ACTIVE).

Import​

Existing secrets can be imported using their UUID:

terraform import okustera_secret.database_creds <secret_uuid>