Publish-SHSecret

Publish-SHSecret

SYNOPSIS

Onboards a discovered secret to PAM

SYNTAX

Publish-SHSecret -sourceSecretStoreType <String> -targetSecretStoreType <String> -secretId <String>
 -secretValueType <String> -safeName <String> -pamAccount <Hashtable> [-WhatIf] [-Confirm]
 [<CommonParameters>]

DESCRIPTION

Onboards a secret that Secrets Hub discovered in an external secret store into your PAM solution.

One secret is onboarded per call. Candidates are identified by Get-SHSecret - a secret with an onboardData.status of CANDIDATE can be onboarded.

-pamAccount describes the PAM account to create. Its properties map each account property to either a literal value (@{ type = 'VALUE'; value = '...' }) or a reference to a key within the secret (@{ type = 'KEY_REF'; keyRef = '...' }).

This endpoint is a Beta API and requires an Accept header, which the module sends for you.

EXAMPLES

Example 1

Publish-SHSecret -sourceSecretStoreType AWS_ASM -targetSecretStoreType PAM_PCLOUD `
    -secretId secret-a94a8fe5-ccb1-9ba6-1c4c-0873d391e987982fbbd3 `
    -secretValueType PLAINTEXT -safeName my-safe -pamAccount @{
        name                       = 'accountName'
        platformId                 = 'WinServerLocal'
        automaticManagementEnabled = $true
        properties                 = @{
            username = @{ type = 'VALUE'; value = 'example username' }
            address  = @{ type = 'VALUE'; value = 'example address' }
        }
    }

Onboards a plaintext secret from AWS Secrets Manager to Privilege Cloud

Example 2

Publish-SHSecret -sourceSecretStoreType AZURE_AKV -targetSecretStoreType PAM_PCLOUD `
    -secretId $secretId -secretValueType JSON -safeName my-safe -pamAccount @{
        name       = 'accountName'
        platformId = 'WinServerLocal'
        properties = @{
            username = @{ type = 'KEY_REF'; keyRef = 'username' }
            password = @{ type = 'KEY_REF'; keyRef = 'password' }
        }
    }

Onboards a JSON secret, mapping account properties to keys within it

PARAMETERS

-sourceSecretStoreType

The type of secret store the secret is onboarded from.

Type: String
Parameter Sets: (All)
Aliases: 
Accepted values: AWS_ASM, GCP_GSM, AZURE_AKV, HASHICORP_VAULT, HASHICORP_VAULT_ENT

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-targetSecretStoreType

The PAM solution the secret is onboarded to.

Type: String
Parameter Sets: (All)
Aliases: 
Accepted values: PAM_PCLOUD, PAM_SELF_HOSTED

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-secretId

The unique identifier of the secret in Secrets Hub.

Type: String
Parameter Sets: (All)
Aliases: id

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-secretValueType

How the secret value is structured.

Type: String
Parameter Sets: (All)
Aliases: 
Accepted values: PLAINTEXT, JSON, TEMPLATE

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-safeName

The name of the PAM Safe to onboard the account into.

Type: String
Parameter Sets: (All)
Aliases: 

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-pamAccount

The PAM account to create - its name, platform ID, whether the CPM manages it automatically, and its properties.

Type: Hashtable
Parameter Sets: (All)
Aliases: 

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

OUTPUTS

NOTES