Skip to content

ybd_secrets_manager (string)

This configuration variable controls where the database looks up secrets to retrieve keys used for encrypting and decrypting sensitive data. The valid values are:

  • none: Encryption functions will not operate
  • k8ss: Use the Kubernetes secrets manager
  • vault: Use the HashiCorp Vault running on an appliance

The value should not need to be changed from the default. It must be set at a system level and configuration reloaded for it to take effect.