Secrets Manager¶
Use dataikuapi.DSSClient.get_secrets_manager() to obtain a Secrets
Manager handle. Secrets are identified by their identifier. A returned
dataikuapi.secretsmanager.secretsmanager.DSSSecret exposes its
metadata as properties and persists editable properties with
dataikuapi.secretsmanager.secretsmanager.DSSSecret.save().
For example, to create and share a local secret:
secrets_manager = client.get_secrets_manager()
secret = secrets_manager.create_local_secret(
identifier="snowflake-password",
secret_value="initial-value",
description="Password used by the Snowflake connection",
)
secret.share_with_user(
"alice",
can_use=True,
can_read=False,
can_write=True,
).save()
The capability attributes are properties. They indicate what the current authentication context can do with the secret:
secret = secrets_manager.get_secret("snowflake-password")
print(secret.can_use)
print(secret.can_read)
print(secret.can_write)
print(secret.can_admin)
To update metadata, modify the corresponding properties on the secret handle and save it. There is no separate metadata object.
secret.description = "Rotated Snowflake password"
secret.save()
Reading a secret value¶
Use dataikuapi.secretsmanager.secretsmanager.DSSSecret.get_value() on
the generic secret handle to read a value. This is the expected way to access
a secret value: it works for both local and vault-backed secrets, and remains
valid if the secret has a different backing type on another DSS instance. The
caller needs Reveal permission. The optional context is included in the audit
event.
secret = secrets_manager.get_secret("snowflake-password")
value = secret.get_value(context={"operation": "connection-test"})
Typed handles are only needed for operations specific to a secret type. For example, use a local-secret handle to rotate a locally stored value:
local_secret = secret.get_as_local_secret()
local_secret.update_value(
"rotated-value",
context={"operation": "credential-rotation"},
)
Use a vault-secret handle only when you need to inspect or edit its vault ID, remote secret identifier, or pinned version. Calling a typed-handle method for the wrong backing type raises an error.
If saving metadata or sharing changes would remove the current caller’s
effective Admin permission, pass confirm_losing_admin_access=True to
dataikuapi.secretsmanager.secretsmanager.DSSSecret.save().
