IdentityCommand.SecretsManager

IdentityCommand.SecretsManager is a PowerShell module that provides a set of easy-to-use commands, allowing you to interact with the Idira Secrets Manager, SaaS API and Secure Workload Access (SWA) API from within the PowerShell environment.

It builds on IdentityCommand for authentication - see Getting Started to install and connect, and the command reference for every command.

Groups and Workloads

Add-SMGroupMember -identifier 'data/myapps/app-admins' -id 'data/GitHub' -kind workload
Remove-SMGroupMember -identifier 'data/myapps/app-admins' -kind workload -id 'data/GitHub'

Remove-SMWorkloadAnnotation -identifier 'data/host1' -annotationName 'env'
Remove-SMWorkload -identifier 'data/host1'

Issuers and Certificates

An issuer creates dynamic secrets or certificates. The parameters that apply depend on the issuer type:

# AWS - static access key credentials
New-SMIssuer -id 'aws-issuer-1' -access_key_id $AccessKeyId -secret_access_key $SecretAccessKey

# GCP - a reference to an already-stored service account key
New-SMIssuer -id 'gcp-issuer-1' -service_account_key_secret_ref 'data/gcp-service-account-key'

# Certificate Manager
New-SMIssuer -id 'cert-man-issuer-1' -service_account_token_url $TokenUrl `
    -user_id_secret_ref 'data/vault/my-safe/venafi/username' -password_secret_ref 'data/vault/my-safe/venafi/password' `
    -default_zone 'Idira\default' -allowed_zones 'Idira\default', 'Idira\ZTPKI'

Get-SMIssuer
Set-SMIssuer -issuerName 'aws-issuer-1' -max_ttl 3000
Remove-SMIssuer -issuerName 'aws-issuer-1'

Only a Certificate Manager issuer can issue or sign certificates:

New-SMIssuedCertificate -issuerName 'cert-man-issuer-1' -common_name 'rest.example.com' -key_type EC_P256
New-SMSignedCertificate -issuerName 'cert-man-issuer-1' -csr $Csr

Authenticators

New-SMAuthenticator -type jwt -subtype gitlab -name 'my_jwt_authn1' -jwks_uri 'https://gitlab.com/oauth/discovery/keys' -audience conjur

Get-SMAuthenticator
Get-SMAuthenticator -type jwt -name 'my_jwt_authn1'

Set-SMAuthenticatorState -type jwt -name 'my_jwt_authn1' -enabled $false
Remove-SMAuthenticator -type jwt -name 'my_jwt_authn1'

Secrets

Get-SMSecretValue -id 'data/vault/mysafe/myaccount/password', 'data/static_secret'
Get-SMSecretValue -id 'data/vault/mysafe/myaccount/password' -encode_values

SWA: Trust Domains, Server Groups, Node Groups and Servers

SWA registers servers into a hierarchy: a trust domain contains server groups, a server group contains node groups (which control workload identity issuance) and the servers themselves.

New-SMTrustDomain -name 'prod.example.com' -signing_key_type EC_P256 -workload_ttl 3600

New-SMServerGroup -trustDomainName 'prod.example.com' -Name 'production-servers' `
    -aws_iid_assume_role 'SWAServerRole' -aws_iid_partition aws

New-SMNodeGroup -trustDomainName 'prod.example.com' -serverGroupName 'production-servers' `
    -Name 'production-nodes' -workload_type unix

New-SMServer -trustDomainName 'prod.example.com' -serverGroupName 'production-servers' `
    -Name 'production-server-1' -sub 'system:serviceaccount:default:my-sa' -jwks_uri 'https://k8s/.well-known/jwks'
Get-SMTrustDomain
Get-SMServerGroup -trustDomainName 'prod.example.com'
Get-SMNodeGroup -trustDomainName 'prod.example.com' -serverGroupName 'production-servers'
Get-SMServer -trustDomainName 'prod.example.com' -serverGroupName 'production-servers'

Each level can be updated or removed - Set-SMTrustDomain, Set-SMServerGroup, Set-SMNodeGroup, Set-SMServer, and the matching Remove-* commands.

SWA: Signing Keys and CA Bundles

These three are public - no authentication is required:

Get-SMCABundle -trustDomainName 'prod.example.com' -format pem
Get-SMOpenIDConfiguration -trustDomainName 'prod.example.com'
Get-SMJwks -trustDomainName 'prod.example.com'