Skip to main content

Manage access to Secrets Manager

Access to Secrets Manager is governed by:

Access within projects

All secrets in Secrets Manager are added in a specific project. You can group secrets by different projects and configure user permissions based on which projects they need access to.

Access within roles

Access to Secrets Manager is granted by Secrets Manager roles and global roles. Read more about role types in the Role Reference.

Role groupRoleAccess
Secrets Manager rolessecrets.adminSecrets management
secrets.viewerViewing secrets
secrets.consumerViewing and using secrets
Global rolesmemberManagement of Secrets Manager and other products, account, billing, and projects
iam.adminManagement of access to Secrets Manager and other products
iam.viewerViewing access to Secrets Manager and other products
readerViewing secrets of Secrets Manager and all products, account, billing, and projects

Secrets Manager roles

secrets.admin

The secrets.admin role grants access to manage secrets in Secrets Manager.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations in Secrets Manager

In the Account access scope:

  • managing secrets (adding, deleting) in all projects;
  • managing secret versions (adding, changing the current version, deleting) in all projects;
  • viewing secret content in all projects

In the Project access scope:

  • managing secrets (adding, deleting) in your project;
  • managing secret versions (adding, changing the current version, deleting) in your project;
  • viewing secret content in your project

secrets.viewer

The secrets.viewer role grants access to view everything that secrets.admin manages.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations in Secrets Manager

In the Account access scope:

  • viewing the list of secrets and information about them, excluding secret content, in all projects

In the Project access scope:

  • viewing the list of secrets and information about them, excluding secret content, in your project

secrets.consumer

The secrets.consumer role grants access to view and use secrets in Secrets Manager.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations in Secrets Manager

In the Account access scope:

  • viewing the list of secrets and information about them in all projects;
  • viewing secret content in all projects

In the Project access scope:

  • viewing the list of secrets and information about them in your project;
  • viewing secret content in your project

Global roles

member

The member role grants full access to all services. It does not grant access to manage panel users, service users, user groups and federations.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations in Secrets Manager

In the Account access scope:

  • managing secrets (adding, deleting) in all projects;
  • managing secret versions (adding, changing the current version, deleting) in all projects;
  • viewing secret content in all projects

In the Project access scope:

  • managing secrets (adding, deleting) in your project;
  • managing secret versions (adding, changing the current version, deleting) in your project;
  • viewing secret content in your project

iam.admin

The iam.admin role grants access to manage users and does not grant access to manage products and billing. It does not allow managing your own account: changing permissions, managing notifications, deleting a user. The first user with the iam.admin role is created by the Account Owner.

Access scopesAccount
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations in Secrets ManagerManaging panel users, service users and user groups

iam.viewer

The iam.viewer role grants access to view everything that iam.admin manages.

Access scopesAccount
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations in Secrets ManagerViewing panel users, service users and user groups

reader

The reader role grants access to view everything that member manages in the same access scope.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations in Secrets Manager

In the Account access scope:

  • viewing the list of secrets and information about them, excluding secret content, in all projects

In the Project access scope:

  • viewing the list of secrets and information about them, excluding secret content, in your project