Skip to content

08. Using a secret manager service

Thierry Feuzeu edited this page Oct 7, 2026 · 2 revisions

Jaxon DbAdmin allows the database credentials to be stored in a secret management service.

Connecting to a secret management server requires two config options. The reader class is provided by the application, and implements the service support. The key class is provided by the user, and returns the path to a given secret. Each service additionally requires its own connection options, to be provided as environment variables. Some service optionally require a custom connection process.

The Universal Auth must be configured on the Infisical server.

use Lagdo\DbAdmin\Support\Facade\Auth;
use Lagdo\DbAdmin\Support\Provider\Secret;

return [
    ...
    'secret' => [
        'reader' => Secret\InfisicalConfigProvider::class,
        'key' => fn() => new class implements Provider\Secret\KeyBuilderInterface {
            public function build(string $prefix, string $option = ''): string
            {
                // $username = Auth::userId(); // Use this to customize the key.
                return "users.{$prefix}.{$option}";
            }
        },
    ],
    ...
];

The following environment variables must be set in the .env.dbadmin file.

INFISICAL_SERVER_URL=
INFISICAL_PROJECT_ID=
INFISICAL_MACHINE_CLIENT_ID=
INFISICAL_MACHINE_CLIENT_SECRET=
INFISICAL_PROJECT_ENV=
use Lagdo\DbAdmin\Support\Facade\Auth;
use Lagdo\DbAdmin\Support\Provider\Secret;

return [
    ...
    'secret' => [
        'reader' => Secret\AwsSecretConfigProvider::class,
        'key' => fn() => new class implements Provider\Secret\KeyBuilderInterface {
            public function build(string $prefix, string $option = ''): string
            {
                // $username = Auth::userId(); // Use this to customize the key.
                // A single entry stores the user name and password in a json payload.
                return "users.{$prefix}";
            }
        },
    ],
    ...
];

The following environment variables must be set in the .env.dbadmin file.

AWS_SECRETS_SERVER_URL=
AWS_SECRETS_REGION=
AWS_SECRETS_VERSION=

# Authentify with client credentials.
# AWS_SECRETS_CLIENT_KEY=
# AWS_SECRETS_CLIENT_SECRET=

# Authentify with a saved profile.
AWS_SECRETS_CLIENT_PROFILE=
use Lagdo\DbAdmin\Support\Facade\Auth;
use Lagdo\DbAdmin\Support\Provider\Secret;

return [
    ...
    'secret' => [
        'reader' => Secret\GcpSecretConfigProvider::class,
        'key' => fn() => new class implements Provider\Secret\KeyBuilderInterface {
            public function build(string $prefix, string $option = ''): string
            {
                // $username = Auth::userId(); // Use this to customize the key.
                return "db.users.{$prefix}.{$option}";
            }
        },
    ],
    ...
];

The following environment variables must be set in the .env.dbadmin file.

GCP_SECRETS_SERVER_URL=
GCP_SECRETS_PROJECT_ID=
GCP_SECRETS_VERSION=
GOOGLE_APPLICATION_CREDENTIALS=
use Lagdo\DbAdmin\Support\Facade\Auth;
use Lagdo\DbAdmin\Support\Provider\Secret;

return [
    ...
    'secret' => [
        'reader' => Secret\OpenBaoConfigProvider::class,
        'key' => fn() => new class implements Provider\Secret\KeyBuilderInterface {
            public function build(string $prefix, string $option = ''): string
            {
                // $username = Auth::userId(); // Use this to customize the key.
                // The key is prefixed with "data/", for the KV2 API.
                return "data/db.users.{$prefix}.{$option}";
            }
        },
    ],
    ...
];

The following environment variables must be set in the .env.dbadmin file.

OPENBAO_AUTH_TOKEN=
OPENBAO_AUTH_USERNAME=
OPENBAO_AUTH_PASSWORD=
OPENBAO_AUTH_ROLE_ID=
OPENBAO_AUTH_SECRET_ID=
OPENBAO_NAMESPACE=
OPENBAO_PROJECT_ID=
OPENBAO_SERVER_PATH=
OPENBAO_SERVER_URL=
use Lagdo\DbAdmin\Support\Facade\Auth;
use Lagdo\DbAdmin\Support\Provider\Secret;

return [
    ...
    'secret' => [
        'reader' => Secret\AzureVaultConfigProvider::class,
        'key' => fn() => new class implements Provider\Secret\KeyBuilderInterface {
            public function build(string $prefix, string $option = ''): string
            {
                // $username = Auth::userId(); // Use this to customize the key.
                return 'db-users-' . str_replace('.', '-', $prefix) . "-$option";
            }
        },
    ],
    ...
];

The following environment variables must be set in the .env.dbadmin file.

AZURE_VAULT_TENANT_ID=
AZURE_VAULT_CLIENT_ID=
AZURE_VAULT_CLIENT_SECRET=
# The vault name is included in the URL
AZURE_VAULT_SERVER_URL=
use Lagdo\DbAdmin\Support\Facade\Auth;
use Lagdo\DbAdmin\Support\Provider\Secret;

return [
    ...
    'secret' => [
        'reader' => Secret\AlibabaKmsConfigProvider::class,
        'key' => fn() => new class implements Provider\Secret\KeyBuilderInterface {
            public function build(string $prefix, string $option = ''): string
            {
                // $username = Auth::userId(); // Use this to customize the key.
                return "db.users.{$prefix}.{$option}";
            }
        },
    ],
    ...
];

The following environment variables must be set in the .env.dbadmin file.

ALIBABA_CLOUD_ACCESS_KEY_ID=
ALIBABA_CLOUD_ACCESS_KEY_SECRET=
# ALIBABA_CLOUD_REGION=
ALIBABA_CLOUD_SERVER_URL=

Clone this wiki locally