IdentityCommand.SecretsHub is a PowerShell module that provides a set of easy-to-use commands, allowing you to interact with the Idira Secrets Hub API from within the PowerShell environment.
It builds on IdentityCommand for authentication - see Getting Started to install and connect, and the command reference for every command.
Secret Stores
A secret store is either the source the secrets sync from (PAM_PCLOUD, PAM_SELF_HOSTED - one per tenant) or a target they are scanned in and synced to (AWS_ASM, AZURE_AKV, GCP_GSM, HASHICORP_VAULT, HASHICORP_VAULT_ENT):
# All stores, or one by id
Get-SHSecretStore
Get-SHSecretStore -storeId store-5a05468b-fa58-4bcf-84e9-62ede8af55f4
# Filtered, either with an expression or from criteria
Get-SHSecretStore -filter 'type EQ AWS_ASM'
Get-SHSecretStore -FilterCriteria @(
@{ Field = 'type'; Operator = 'EQ'; Value = 'AWS_ASM' }
@{ Field = 'state'; Operator = 'EQ'; Value = 'ENABLED' }
)
The connection details of a store depend on its type, so they travel as a hashtable:
New-SHSecretStore -type AWS_ASM -name 'Account alias - us-east-1' -data @{
accountAlias = 'my-account-alias'
accountId = '123456789012'
regionId = 'us-east-1'
roleName = 'Secrets-Hub-IAM-Role'
}
Set-SHSecretStore -storeId $storeId -description 'Updated description'
Test-SHSecretStoreConnection -storeId $storeId
Remove-SHSecretStore -storeId $storeId
Stores are enabled and disabled one at a time, or up to 500 together - the bulk form reports a result per store, so a partial success is normal:
Set-SHSecretStoreState -storeId $storeId -action disable
(Set-SHSecretStoreState -secretStoreIds $Ids -action enable).results | Where-Object result -eq FAILURE
Secrets
Get-SHSecret returns what the scans have discovered:
Get-SHSecret
# The Secrets Hub query language: clauses joined with AND, no OR, no parentheses
Get-SHSecret -filter 'storeName CONTAINS prod'
# Or build the expression from criteria - values are quoted for you
Get-SHSecret -FilterCriteria @(
@{ Field = 'vendorType'; Operator = 'EQ'; Value = 'AWS' }
@{ Field = 'onboardData.status'; Operator = 'EQ'; Value = 'CANDIDATE' }
)
# Vendor-specific data - tags, rotation metadata, regions
Get-SHSecret -projection EXTEND
A discovered secret that is a candidate can be onboarded into PAM, and an unmanaged secret can be deleted from the target store it lives in:
Publish-SHSecret -sourceSecretStoreType AWS_ASM -targetSecretStoreType PAM_PCLOUD `
-secretId $secretId -secretValueType PLAINTEXT -safeName my-safe -pamAccount @{
name = 'accountName'
platformId = 'WinServerLocal'
automaticManagementEnabled = $true
properties = @{
username = @{ type = 'VALUE'; value = 'example username' }
password = @{ type = 'KEY_REF'; keyRef = 'password' }
}
}
Remove-SHSecret -secretId $secretId
Sync Policies
A sync policy defines which secrets sync from the source store to a target store. Each needs a secrets filter naming the PAM Safe; giving -safeName defines it inline and avoids the deprecated filters endpoints:
New-SHSyncPolicy -name 'Dev Team1 Policy' -sourceId $sourceStoreId -targetId $targetStoreId -safeName my-safe
Get-SHSyncPolicy
Get-SHSyncPolicy -filter 'filter.safeName EQ MySafeName'
Get-SHSyncPolicy -policyId $policyId -projection EXTEND
Set-SHSyncPolicyState -policyId $policyId -action disable
Remove-SHSyncPolicy -policyId $policyId
Scans, Configuration and Transformations
Start-SHScan -secretStoresIds $storeId
Get-SHConfiguration
Set-SHConfiguration -secretValidity 400
Set-SHConfiguration -gcpReplicationRegion us-central1, europe-west1
Get-SHTransformation -transformationId $transformationId