VaultConfig
class resources.vault_config.VaultConfig
Base class: Resource
A configuration about a HashiCorp Vault which Cloudomation can access to fetch secrets.
Either a vault token, client certificate or userpass authentication method can be used. Currently, only the Key-Value engine version 2 is supported.
See the corresponding Flow Api class at VaultConfig
| Property | Description | Type | Import/Export | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| bundle_id | Reference to the bundle this record is associated with. Allowed for BUNDLE_REPOSITORY, CONNECTOR, CUSTOM_OBJECT, DASHBOARD, DEVOLUTIONS_CONFIG, EXECUTION, FILE, FLOW, LDAP_CONFIG, MCP_USER_TOOL, MESSAGE, OBJECT_TEMPLATE, PLUGIN, PYTHON_MODULE, ROLE, SCHEDULE, SCHEDULER, SCHEMA, SETTING, SYNC_CONFIG, TAG, VAULT_CONFIG, WEBHOOK, WRAPPER. Not allowed for BUNDLE, ORGANIZATION, PROCESS, PROJECT, USER, WORKSPACE. Mutually exclusive with project_id | UUID(as_uuid=False) | both | |||||||||||||||
| bundle_name | The name of the bundle. Will look up the bundle and set bundle_id. | String(length=128) | import only | |||||||||||||||
| check_hostname | If set, the hostname of the server is checked against the CA certificate. | Boolean() | both | |||||||||||||||
| children | Subrecords to create in the SAME transaction as the record, as a mapping of {subrecord_type: [ {column: value, ...}, ... ]}. A generic, schema-derived create-with-children: a key is accepted iff it names a subrecord type whose parent is one of this record's ancestor tables — e.g. an object_template with object_template_attribute rows, a role with role_permission rows, or a flow with resource_wrapper rows. The parent foreign key (<parent>_id) is auto-wired to the new record; each child is validated by its own subrecord create-path. Passing children inline makes the record and its subrecords atomic (any child failure rolls the whole create/update back), replacing a create-then-add-N sequence with one round-trip. Exposed identically on REST create/update bodies and the GraphQL create_<type>/update_<type> mutation input (as an arbitrary-JSON scalar), and via MCP create_record/update_record, since it is a single schema-derived column with no per-surface code. Accepted on both create and update. Nesting to arbitrary depth IS supported: a child entry may itself carry a children key, validated recursively against THAT child subrecord type's own ancestor tables and created depth-first in the same transaction. (Under the current subrecord model the only externally-creatable chains happen to be one level deep — subrecords are not record-backed, so e.g. a record_metadata cannot be nested under an object_template_attribute — but the recursion is applied generically so any deeper externally-creatable chain works with no per-type code.) On read the children are exposed via their subrecord lists, not this field. | JSONEncodedData() | neither | |||||||||||||||
| client_cert | A client certificate used to authenticate the SSL transport. | String(length=40960) | both | |||||||||||||||
| client_key | The key of the client certificate used to authenticate the SSL transport. | String(length=40960) | import only | |||||||||||||||
| commit_message | The commit message for this change. | Text() | import only | |||||||||||||||
| created_at | DateTime(timezone=True) | export only | ||||||||||||||||
| created_by | UUID(as_uuid=False) | export only | ||||||||||||||||
| deleted_at | When the record was moved to the trashbin. Null while the record is active. | DateTime(timezone=True) | import only | |||||||||||||||
| deleted_by | UUID(as_uuid=False) | import only | ||||||||||||||||
| description | A multiline description of what this record is and does. | Text() | both | |||||||||||||||
| engine_path | The Vault engine to use, often secret or kv. | String(length=1024) | both | |||||||||||||||
| has_client_key | Boolean() | neither | ||||||||||||||||
| has_deprecation | Boolean() | export only | ||||||||||||||||
| has_password | Boolean() | neither | ||||||||||||||||
| has_syntax_error | Boolean() | export only | ||||||||||||||||
| has_token | Boolean() | neither | ||||||||||||||||
| id | UUID(as_uuid=False) | neither | ||||||||||||||||
| is_auto_renew_enabled | If set, Engine will try to renew the token before it expires. Renewal will only succeed if the MAX_TTL of the token is not reached. Please refer to token renew for details. | Boolean() | both | |||||||||||||||
| is_bundle_content | A flag to control if the resource is considered bundle content. Changes in bundle content mark the bundle as modified. Updating the bundle will modify the bundle content. | Boolean() | both | |||||||||||||||
| is_bundle_readonly | Boolean() | neither | ||||||||||||||||
| is_deleted | Whether the record has been permanently deleted. Records in the trashbin are indicated by deleted_at instead. | Boolean() | export only | |||||||||||||||
| is_enabled | A flag to control of the vault config is enabled. | Boolean() | export only | |||||||||||||||
| is_project_readonly | Boolean() | neither | ||||||||||||||||
| is_readonly | A flag to control if the record can be modified. Allowed for BUNDLE, BUNDLE_REPOSITORY, CONNECTOR, CUSTOM_OBJECT, DASHBOARD, DEVOLUTIONS_CONFIG, FILE, FLOW, MCP_USER_TOOL, OBJECT_TEMPLATE, PLUGIN, PROJECT, PYTHON_MODULE, ROLE, SCHEDULE, SCHEDULER, SCHEMA, SETTING, SYNC_CONFIG, TAG, VAULT_CONFIG, WEBHOOK, WRAPPER. Not allowed for EXECUTION, LDAP_CONFIG, MESSAGE, ORGANIZATION, PROCESS, USER, WORKSPACE | Boolean() | both | |||||||||||||||
| location_inheritance | Controls the project/bundle association of a newly created record when no project_id/project_name/bundle_id/bundle_name is specified in the create request. Depending on the record type different options are available:
| String(length=128) | import only | |||||||||||||||
| modified_at | DateTime(timezone=True) | neither | ||||||||||||||||
| modified_by | UUID(as_uuid=False) | neither | ||||||||||||||||
| name | The name of this record. Must be unique across a workspace. | String(length=128) | both | |||||||||||||||
| organization_id | UUID(as_uuid=False) | export only | ||||||||||||||||
| password | A password to authenticate. Either token, username and password, or client_cert and client_key must be set. | String(length=1024) | import only | |||||||||||||||
| pending_delete_commit | Boolean() | neither | ||||||||||||||||
| pending_delete_identity_id | UUID(as_uuid=False) | neither | ||||||||||||||||
| pending_operation_id | UUID(as_uuid=False) | neither | ||||||||||||||||
| pending_restore_commit | Boolean() | neither | ||||||||||||||||
| pending_restore_identity_id | UUID(as_uuid=False) | neither | ||||||||||||||||
| pending_trash_commit | Boolean() | neither | ||||||||||||||||
| pending_trash_identity_id | UUID(as_uuid=False) | neither | ||||||||||||||||
| project_id | Reference to the project this record is associated with. Allowed for CONNECTOR, CUSTOM_OBJECT, DASHBOARD, DEVOLUTIONS_CONFIG, EXECUTION, FILE, FLOW, MCP_USER_TOOL, MESSAGE, OBJECT_TEMPLATE, PLUGIN, PYTHON_MODULE, SCHEDULE, SCHEDULER, SCHEMA, SETTING, SYNC_CONFIG, TAG, VAULT_CONFIG, WEBHOOK, WRAPPER. Not allowed for BUNDLE, BUNDLE_REPOSITORY, LDAP_CONFIG, ORGANIZATION, PROCESS, PROJECT, ROLE, USER, WORKSPACE. Mutually exclusive with bundle_id. | UUID(as_uuid=False) | both | |||||||||||||||
| project_name | The name of the project. Will look up the project and set project_id. | String(length=128) | import only | |||||||||||||||
| record_metadata | Record metadata to attach in the SAME transaction as the record create/update, as a mapping of {key: data} (key: string up to 128 chars, data: arbitrary JSON). Each entry is written as a record_metadata subrecord, upserted by (record_id, key). This removes the create-then-add race: without it a flow/API must first create the record and then add its metadata in a second call, leaving a window where the record exists un-marked (and may already be committed to git before the marker lands). Passing record_metadata inline makes the record and its metadata atomic. Accepted (and applied) on both create and update. On read the metadata is exposed via the record_metadata subrecord list, not this field. | JSONEncodedData() | neither | |||||||||||||||
| record_type | Enum('EXECUTION', 'MESSAGE', 'PROCESS', 'BUNDLE', 'BUNDLE_REPOSITORY', 'CONNECTOR', 'CUSTOM_OBJECT', 'DASHBOARD', 'DEVOLUTIONS_CONFIG', 'FILE', 'FLOW', 'LDAP_CONFIG', 'MCP_USER_TOOL', 'OBJECT_TEMPLATE', 'ORGANIZATION', 'PLUGIN', 'PROJECT', 'PYTHON_MODULE', 'ROLE', 'SCHEDULE', 'SCHEDULER', 'SCHEMA', 'SETTING', 'SYNC_CONFIG', 'TAG', 'USER', 'VAULT_CONFIG', 'WEBHOOK', 'WORKSPACE', 'WRAPPER', name='recordtype') | neither | ||||||||||||||||
| record_version | Optimistic-concurrency version token. Read-only, computed on read from modified_at at full (microsecond) precision (request it by name; not in the default summary). Pass the value you last read back as expected_version on update to guard against lost updates: if the record changed meanwhile the write is rejected with HTTP 409 (StaleWrite) carrying the current record and token. Not stored; not exported. | Text() | neither | |||||||||||||||
| recurse_pending_delete | Boolean() | neither | ||||||||||||||||
| recurse_pending_restore | Boolean() | neither | ||||||||||||||||
| recurse_pending_trash | Boolean() | neither | ||||||||||||||||
| repository_path | The path to the storing repository, relative to GIT_REPOSITORY_SAVE_PATH | String(length=256) | neither | |||||||||||||||
| resolved_icon | The record's resolved display icon: the concrete subtype's own icon column (dashboard/project/bundle/object_template/workspace/user/plugin_action), or NULL when the subtype carries no icon. Read-only, computed on read (request it by name; not in the default summary); not stored, not exported. Lets the polymorphic base record expose a per-record icon (sidebar quick-access, quick-search, generic record lists) without shadowing the subtype icon columns. Named resolved_icon, not icon, for the same reason record_version is not version: a base virtual column named icon would override the subtype icon columns in their own all_columns (ancestors overwrite descendants), turning them read-only and non-exporting. | Text() | neither | |||||||||||||||
| resource_type | Enum('BUNDLE', 'BUNDLE_REPOSITORY', 'CONNECTOR', 'CUSTOM_OBJECT', 'DASHBOARD', 'DEVOLUTIONS_CONFIG', 'FILE', 'FLOW', 'LDAP_CONFIG', 'MCP_USER_TOOL', 'OBJECT_TEMPLATE', 'ORGANIZATION', 'PLUGIN', 'PROJECT', 'PYTHON_MODULE', 'ROLE', 'SCHEDULE', 'SCHEDULER', 'SCHEMA', 'SETTING', 'SYNC_CONFIG', 'TAG', 'USER', 'VAULT_CONFIG', 'WEBHOOK', 'WORKSPACE', 'WRAPPER', name='resourcetype') | neither | ||||||||||||||||
| schema_version | String(length=128) | both | ||||||||||||||||
| server_ca | The content of the server's CA certificates in PEM format. To be used for self-signed certificates. | String(length=40960) | both | |||||||||||||||
| token | A Vault access token to authenticate. Either token, username and password, or client_cert and client_key must be set. | String(length=1024) | import only | |||||||||||||||
| track_in_git | Should new records automatically be tracked in git. | Boolean() | both | |||||||||||||||
| username | A Username to authenticate. Either token, username and password, or client_cert and client_key must be set. | String(length=1024) | both | |||||||||||||||
| vault_url | The URL to your vault installation | String(length=1024) | both | |||||||||||||||
| verify_ssl | Verify the server's SSL certificate. Strongly recommended. Can be disabled if using a self-signed certificate. | Boolean() | both | |||||||||||||||
| workspace_id | UUID(as_uuid=False) | export only |