On This Page

Home / Stream/ Secure Your Deployment/ Centralize and Reuse Global Secrets/Connect External Secret Stores

Connect External Secret Stores

An externally backed secret store connects Cribl to an external provider that already holds your credentials. Every secret folder in the secret store uses the external provider as its backing store. The global secrets that you add to the secret store hold references to secrets in the external provider rather than secret values. The external provider remains the system of record for the credentials.

Cribl persists the secret store configuration and the global secret references on the Leader, but not the secret values. The Leader resolves each reference against the external provider and distributes the resolved values to Worker Groups and Edge Fleets.

You can add externally backed secret stores for the following providers:

Each secret store connects to one external provider, and you can add more than one secret store for the same provider. Configure the secret store first, then add secret folders and global secrets that reference the secrets from the external provider.