You can create a Resource Access Management (RAM) secret that is automatically rotated on a regular basis. This reduces the risks of RAM secret leaks. This topic describes how to create, delete, and restore a dynamic RAM secret in the Key Management Service (KMS) console.
Prerequisites
- An Alibaba Cloud account or a RAM user or RAM role that has permissions to manage
dynamic RAM secrets is obtained.
If you use a RAM user or RAM role to manage dynamic RAM secrets, you must attach the system policies AliyunKMSSecretAdminAccess and AliyunRAMFullAccess to the RAM user or the RAM role.
- Secrets Manager is authorized to manage the AccessKey pairs of RAM users. You must use a RAM service role to grant Secrets Manager the permissions. For more information, see Authorize Secrets Manager to manage AccessKey pairs of RAM users.
- An AccessKey pair is created for the RAM user for which you want to create a dynamic RAM secret. For more information, see Create an AccessKey pair for a RAM user.
Create a dynamic RAM secret
Delete a dynamic RAM secret
Before you delete a dynamic RAM secret, make sure that the dynamic RAM secret is no longer used.
You can schedule the deletion of a dynamic RAM secret or immediately delete a dynamic RAM secret. If you delete a dynamic RAM secret, the system does not delete the AccessKey pair of the RAM user that is associated with the secret.
- In the left-side navigation pane, click Secrets.
- Find the dynamic RAM secret that you want to delete and choose Actions column. in the
- In the Delete Secret dialog box, select a method to delete the secret and click OK.
- If you select Plan Deletion Secret, you must configure the Delete In (7-30 days) parameter. Then, the system deletes the secret after the specified number of days.
Before the system deletes the secret, you can restore the secret to cancel deletion. For more information, see Restore a dynamic RAM secret.
- If you select Delete Secret Immediately, the system immediately deletes the secret.
- If you select Plan Deletion Secret, you must configure the Delete In (7-30 days) parameter. Then, the system deletes the secret after the specified number of days.
Restore a dynamic RAM secret
If you schedule a dynamic RAM secret to be deleted, you can restore the secret to cancel deletion before the system deletes the secret. After the dynamic RAM secret is restored, it can be used as normal.
- In the left-side navigation pane, click Secrets.
- Find the dynamic RAM secret that you want to restore and choose Actions column. in the
- In the Restore Secret message, click OK.