Using Vault for Managing Secrets

OCI Vault is a key management service that stores and manages master encryption keys and secrets for secure access to resources. When you provision a Siebel CRM environment using SCM, you must provide sensitive information in several places. Instead of entering sensitive values directly in the environment payload, you can store them as secrets in OCI Vault and provide their Oracle Cloud Identifier (OCID) values in the payload. SCM uses the OCIDs to fetch the actual secret values when required.

For more information about OCI Vault services, refer Overview of Vault.

For use with SCM, you can provision Vault in one of the following ways:

  • Bring your own OCI Vault: In this case, you must provide your existing vault's OCID. Optionally, specify the OCID of a customer-managed KMS key during SCM stack creation. If you do not specify a key, SCM uses Oracle-managed encryption keys to encrypt SCM and Siebel file storage.

    SCM uses separate KMS key OCID inputs for SCM storage and Siebel environment file storage:

    • BYO KMS key OCID: Use this key to provide the KMS key OCID for SCM storage. SCM uses this key to encrypt the SCM boot volume and SCM file storage.
    • siebel_storage_kms_key_ocid: Use this parameter in the infrastructure section of the Siebel environment payload to encrypt Siebel environment file storage.

    To use customer-managed KMS keys, you must create the required dynamic groups and IAM policies for the applicable resources. For more information on configuring dynamic groups and policies, see Configuring Customer-Managed KMS Keys for Infrastructure Resources Created by SCM.

    Note: You must use the correct OCID type when you configure Vault and storage encryption:
    • A Vault OCID starts with ocid1.vault and identifies an OCI Vault.
    • A Vault Secret OCID starts with ocid1.vaultsecret and identifies a stored secret, such as a password.
    • A KMS key OCID starts with ocid1.key and identifies the customer-managed KMS key used by OCI storage resources.
  • Have SCM provision a new Vault: You do not need to provide Vault information. SCM provisions a new Vault during stack creation. You can choose to create a default Vault or a virtual private Vault.

If you bring your own Vault, make sure SCM has the required access to fetch secrets from the Vault. For more information about the required policies, see Common Policies.

After SCM stack creation is complete, the Vault is available for use. You must complete the following steps before you provision a new Siebel CRM environment:

  1. Create a Master Encryption Key (MEK) in the Vault.
  2. Create secrets using the MEKs for the necessary fields in the payload section.
  3. Copy the OCIDs of the secrets created in step 2 and provide them as input in the payload section.