Skip to content

Configure a Connection with HashiCorp Vault

This page walks through the Secrets Management group of the connection form and the ${key} references that use the secret. It applies to every connector; the connector's own page documents the rest of its form.

No secret, policy, or role yet?

Set them up first in Prepare Vault. The values you need here come out of those steps.

Before you start, confirm with your network team that the addresses listed below the connection form can reach Vault, and that Vault's hostname resolves from inside the Qualytics deployment. See Network Requirements.

Steps

Step 1: Start adding a datastore and choose New Connection. Secrets management belongs to the connection, so it is read-only when you reuse an existing one.

Step 2: Under Secrets Management, turn on HashiCorp Vault.

Step 3: Fill in the six fields. The values below match the example in Prepare Vault; replace the host, namespace, mount, and secret name with yours.

Field Value
Login URL https://vault.example.com/v1/auth/approle/login, or https://vault.example.com/v1/<namespace>/auth/approle/login when the AppRole lives in a namespace
Credentials Payload {"role_id": "<role_id>", "secret_id": "<secret_id>"}
Token JSONPath $.auth.client_token
Secret URL https://vault.example.com/v1/secret/data/qualytics/postgres, or with the namespace after /v1/. Build it from the API path on the secret's Paths tab, with https:// and the host in front
Token Header Name X-Vault-Token
Data JSONPath $.data.data for a KV version 2 secret (its API path contains /data/); $.data for KV version 1 or the database secrets engine. Change the pre-filled $.data if needed

Both URLs must be complete, starting with https:// and including the host. A bare path is not accepted.

Step 4: In the Connection Properties and Authentication fields, enter ${key} wherever a value should come from the secret, for example ${username} and ${password}. Use braces, not $.key, and match the key name's case exactly. Only names made of letters, digits, and underscores, starting with a letter or underscore, can be referenced; see Referencing the Secret.

Step 5: Fill in the connector's remaining fields as documented on its page, then click Test connection. A successful test means Qualytics logged in to Vault, read the secret, substituted every reference, and reached the data source with the result.

Step 6: If the test fails, match the message in the banner to its entry in Troubleshooting, fix the cause, and test again.

Step 7: Click Next to continue with the datastore, then Finish.

Changing a credential later

Change it in Vault. Qualytics fetches the secret every time the connection is opened, so nothing needs to be edited here. If you rotate the AppRole secret ID, update only the Credentials Payload.