Key Management (KMS)

Entry: /kms, then Keys & secrets or Certificates. KMS stores Group-scoped credentials, private keys and certificates. You need an enabled, licensed Module and the appropriate Group access. Reading metadata, managing records and revealing secret material are separate permissions.

Store a credential or certificate

  1. Select the correct Group and open the appropriate inventory. Choose Add secret.
  2. Select Secret type and enter Name, optional Target / device, Username and expiry. Names, targets, usernames and notes are readable metadata: never put a password in these fields.
  3. Enter the value in Secret value, or use the dedicated private-key/certificate fields. For a certificate chain, place the leaf certificate first. A supplied private key must match it; expiry comes from the certificate.
  4. Choose Add secret and confirm the new metadata row. The stored credential does not change the target system.

Reveal and replace a value

  1. Open the record's Settings → Reveal secret. Confirm the reveal action only when you need the current material.
  2. Read the value in the reveal dialog. Access is recorded; the displayed material clears after 30 seconds, or when the dialog closes or the page is hidden.
  3. To replace stored material, choose Settings → Replace secret and provide the complete new value or bundle. Review the target and submit.
  4. Update or rotate the credential on the actual target through your approved operational process, and verify that the stored value matches the intended target state.

Retire a secret deliberately

  1. Use Edit metadata for descriptive changes; it does not replace secret material.
  2. Choose Archive secret when the record should no longer be revealed or replaced. Revoke target access separately if required.
  3. An archived record can be deleted using Delete secret and its exact name. Review this carefully: live material is removed, while backup and audit retention follow their separate policies.

Blockers and limits: missing reveal permission, an archived record, a stale version or unavailable installation encryption custody can block the action. Ask the responsible administrator to investigate without sending them the secret in a support message. KMS permits 1,000 retained records and 8 MiB of material across the installation, including archives, with 64 KiB per record; over-limit writes are rejected. KMS does not provide automatic target rotation, certificate renewal, secret-history recovery or secret export.