1"use strict";(self.webpackChunkfluvio_docs=self.webpackChunkfluvio_docs||[]).push([[2586],{11894:(e,n,t)=>{t.r(n),t.d(n,{assets:()=>a,contentTitle:()=>r,default:()=>p,frontMatter:()=>c,metadata:()=>i,toc:()=>l});var s=t(74848),o=t(28453);const c={sidebar_position:6,title:"Secrets",description:"Manage sensitive information in your Connector using Secrets."},r=void 0,i={id:"connectors/developers/secrets",title:"Secrets",description:"Manage sensitive information in your Connector using Secrets.",source:"@site/versioned_docs/version-0.18.0/connectors/developers/secrets.mdx",sourceDirName:"connectors/developers",slug:"/connectors/developers/secrets",permalink:"/docs/0.18.0/connectors/developers/secrets",draft:!1,unlisted:!1,editUrl:"https://github.com/infinyon/fluvio-docs/tree/main/versioned_docs/version-0.18.0/connectors/developers/secrets.mdx",tags:[],version:"0.18.0",lastUpdatedBy:"Felipe Cardozo",lastUpdatedAt:1752028303e3,sidebarPosition:6,frontMatter:{sidebar_position:6,title:"Secrets",description:"Manage sensitive information in your Connector using Secrets."},sidebar:"connectors",previous:{title:"Logging",permalink:"/docs/0.18.0/connectors/developers/logging"},next:{title:"Publish to Hub",permalink:"/docs/0.18.0/connectors/developers/publish"}},a={},l=[{value:"Use Secrets",id:"use-secrets",level:3}];function d(e){const n={a:"a",blockquote:"blockquote",code:"code",h3:"h3",p:"p",pre:"pre",...(0,o.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsxs)(n.blockquote,{children:["\n",(0,s.jsxs)(n.p,{children:["This section assumes ",(0,s.jsx)(n.code,{children:"my-connector"})," project has been ",(0,s.jsx)(n.a,{href:"./generate",children:"generated"}),"."]}),"\n"]}),"\n",(0,s.jsxs)(n.p,{children:["Connectors often connect to external entities such as ",(0,s.jsx)(n.code,{children:"databases"}),", ",(0,s.jsx)(n.code,{children:"message brokers"}),", or ",(0,s.jsx)(n.code,{children:"APIs"})," that require a confidential authentication key."]}),"\n",(0,s.jsxs)(n.p,{children:["Connectors offers this facility through ",(0,s.jsx)(n.code,{children:"secrets"}),"."]}),"\n",(0,s.jsx)(n.h3,{id:"use-secrets",children:"Use Secrets"}),"\n",(0,s.jsx)(n.p,{children:"Let's define a file of secrets (one secret per line) in the following format:"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"SECRET_NAME=SECRET_VALUE\nSECRET_NAME_2=SUPER_SECRET_VALUE\n"})}),"\n",(0,s.jsxs)(n.p,{children:["Deploy connectors with a ",(0,s.jsx)(n.code,{children:"--secrets"})," flag to pass a file with the secrets definitions:"]}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",metastring:'copy="fl"',children:"$ cdk deploy start --config sample-config.yaml --secrets secrets.txt\n"})}),"\n",(0,s.jsxs)(n.p,{children:["Code to indicate that a connector config parameter can contain a secret should use the ",(0,s.jsx)(n.code,{children:"SecretString"})," type. This allows the parameter to receive secrets which are not printable to logs."]}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-rust",children:'use fluvio_connector_common::{connector, secret::SecretString};\n\n#[derive(Debug)]\n#[connector(config, name = "myconnector")]\npub(crate) struct MyConnectorConfig {\n /// A parameter receiving a secret string\n pub a_param: SecretString,\n // -- snip --\n}\n'})}),"\n",(0,s.jsx)(n.p,{children:"This allows a config file to provision secrets to the connector."}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-yaml",children:'# config-example.yaml\napiVersion: 0.1.0\nmeta:\n version: 0.1.0\n name: instancename\n type: my-connector\n topic: atopicname\n secrets:\n - name: SECRET_NAME\nmyconnector:\n a_param: "${{ secrets.SECRET_NAME }}_${{ secrets.SECRET_NAME_2 }}"\n\n'})}),"\n",(0,s.jsxs)(n.p,{children:["More extensive examples of secrets in connectors can be seen in use with the ",(0,s.jsx)(n.a,{href:"/docs/0.18.0/hub/connectors/inbound/http",children:"Http Source"})," connector and the github repo ",(0,s.jsx)(n.a,{href:"https://github.com/infinyon/http-source-connector",children:"https://github.com/infinyon/http-source-connector"}),"."]}),"\n",(0,s.jsx)(n.p,{children:"In the next section, we'll publish our connector to the Hub."})]})}function p(e={}){const{wrapper:n}={...(0,o.R)(),...e.components};return n?(0,s.jsx)(n,{...e,children:(0,s.jsx)(d,{...e})}):d(e)}},28453:(e,n,t)=>{t.d(n,{R:()=>r,x:()=>i});var s=t(96540);const o={},c=s.createContext(o);function r(e){const n=s.useContext(c);return s.useMemo((function(){return"function"==typeof e?e(n):{...n,...e}}),[n,e])}function i(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(o):e.components||o:r(e.components),s.createElement(c.Provider,{value:n},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.