Protecting Secrets Manager resources with context-based restrictions

After you set up your IBM Cloud® Secrets Manager service instance, you can manage access by using context-based restrictions (CBR).

Managing CBR settings

With context-based restrictions, you can define and enforce user and service access restrictions to Secrets Manager resources based on specified criteria.

You can control Secrets Manager resources with context-based restrictions and identity and access management (IAM) policies. These restrictions work with traditional IAM policies, which are based on identity, to provide another layer of protection. For more information, see What are context-based restrictions.

A user must have the Administrator role on the Secrets Manager service to create, update, or delete rules. A user must also have either the Editor or Administrator role on the context-based restrictions service to create, update, or delete network zones. A user with the Viewer role on the context-based restrictions service can add only network zones to a rule.

Any IBM Cloud Activity Tracker or audit log events that are generated come from the context-based restrictions service, not Secrets Manager. For more information, see Monitoring context-based restrictions.

To get started with protecting your Secrets Manager resources with context-based restrictions, see the tutorial for Leveraging context-based restrictions to secure your resources.

How Secrets Manager integrates with context-based restrictions

You can create context-based restrictions (CBR) for Secrets Manager service APIs and platform APIs. With context-based restrictions, you can protect the following API types.

Trial and Standard APIs
Protect access to the APIs used by applications and clients to manage and access standard Secrets Manager resources and perform secret management operations. For example, you can protect the APIs used to manage secret groups, configurations, and notifications registrations, as well as the APIs used to create, read, rotate, or lock secrets and their versions. This API type applies only to instances on the Trial and Standard plans.
Vault Dedicated management APIs
Protect access to the APIs used by applications and clients to manage, configure, and perform administrative operations on Vault Dedicated resources. For example, you can protect the APIs used for admin token creation and revocation. This API type applies only to instances on the Vault Dedicated plan.
Vault Dedicated runtime APIs
Protect access to the APIs used by applications and clients to access and consume Vault Dedicated resources during runtime. This API type applies only to instances on the Vault Dedicated plan.
Platform APIs — Resource management
Protect access to the platform-level APIs used to manage the lifecycle of your Secrets Manager service instance, such as provisioning, de-provisioning, and managing resource keys and bindings.

To restrict access, you must create zones and rules. After you create or update a zone or a rule, it might take a few minutes for the change to take effect.

Protecting specific APIs

You can create CBR rules to protect the following API types for Secrets Manager.

Trial and Standard APIs

Trial and Standard APIs are used by applications and clients to manage and access Secrets Manager resources and perform secret management operations.

CBR rules that apply to the Trial and Standard API type control access to secret management and service administration operations, which include managing secret groups, configurations, destinations, and notifications registrations, viewing instance details and endpoints, and creating, reading, rotating, importing, revoking, and deleting secrets and their versions, managing secret version data, metadata, and policies, and managing locks on secrets and secret versions.

This API type applies only to Secrets Manager instances on the Trial and Standard plans.

If you use the CLI, you can specify the --api-types option and the crn:v1:bluemix:public:secrets-manager::::api-type:standard type.

If you use the API, you can specify "api_type_id": "crn:v1:bluemix:public:secrets-manager::::api-type:standard" in the "operations" spec.

Vault Dedicated management APIs

Vault Dedicated plan management APIs are used by applications and clients to manage, configure, and perform administrative operations on Vault Dedicated resources.

CBR rules that apply to the Vault Dedicated management API type control access to Vault Dedicated administration operations, configuration operations, which include admin token creation and revocation.

This API type applies only to Secrets Manager instances on the Vault Dedicated plan.

If you use the CLI, you can specify the --api-types option and the crn:v1:bluemix:public:secrets-manager::::api-type:vault-dedicated-management type.

If you use the API, you can specify "api_type_id": "crn:v1:bluemix:public:secrets-manager::::api-type:vault-dedicated-management" in the "operations" spec.

Vault Dedicated runtime APIs

Protect access to the APIs used by applications and clients to access and consume Vault Dedicated resources during runtime.

This API type applies only to Secrets Manager instances on the Vault Dedicated plan.

If you use the CLI, you can specify the --api-types option and the crn:v1:bluemix:public:secrets-manager::::api-type:vault-dedicated-runtime type.

If you use the API, you can specify "api_type_id": "crn:v1:bluemix:public:secrets-manager::::api-type:vault-dedicated-runtime" in the "operations" spec.

Platform APIs — Resource management

Protect access to the platform-level APIs used to manage the lifecycle of your Secrets Manager service instance.

If you use the CLI, you can specify the --api-types option and the crn:v1:bluemix:public:secrets-manager::::api-type:platform-resource-management type.

If you use the API, you can specify "api_type_id": "crn:v1:bluemix:public:secrets-manager::::api-type:platform-resource-management" in the "operations" spec.

Creating network zones

To create network zones, follow the steps in Creating context-based restrictions. When you add Secrets Manager as a service reference to a network zone, use secrets-manager as the serviceRef value.

The serviceRef attribute for Secrets Manager is secrets-manager.

Make sure to add Secrets Manager to network zones for rules that target other IBM Cloud resources, or some operations in your workflow might fail.

Understanding rules

To create rules, follow the steps in Creating context-based restrictions. When you create a rule for Secrets Manager, select Secrets Manager as the service, then choose the API types you want to protect under Service APIs or Platform APIs:

Service APIs

  • Standard and Trial — Applies only to instances on the Trial and Standard plans.
  • Vault Dedicated Management — Applies only to Management API's of instances on the Vault Dedicated plan.
  • Vault Dedicated Runtime — Applies only to Runtime API's of instances on the Vault Dedicated plan.

Platform APIs

  • Resource Management - Applies only to Resource Controller and Global Search APIs.

Limitations

Review the following limitations before you create CBR rules for Secrets Manager.

Secret group rules require group-level IAM access
When a user has instance-level IAM access, CBR rules that are applied to specific secret groups do not take effect. To work around this limitation, set the user's IAM access policies to only secret groups.
CBR rules do not apply to provisioning or de-provisioning
CBR rules do not restrict provisioning or de-provisioning operations. Use IAM policies to control who can create or delete Secrets Manager instances.
Some platform API actions are not protected
Context-based restrictions protect actions associated with the Secrets Manager API and the Resource Management API type. The following platform API actions are not protected by context-based restrictions. Refer to the API docs for the specific action IDs.

Next steps

You must follow the creation or modification of zones or rules with adequate testing to ensure access and availability.

Users who attempt to access your resources outside of the defined zones receive HTTP error 401 when the appropriate rules are not established.