AccuKnox Secrets Manager¶
AccuKnox Secrets Manager gives you one secure place to store, manage, and read passwords, API keys, tokens, certificates, and other credentials. It replaces hardcoded secrets with central storage, scoped access, encryption, and a full audit log. It is API-compatible with HashiCorp Vault and runs on any Kubernetes cluster at version 1.30 or later.
-
One place for every secret
Versioned secrets, encryption keys, certificates and one-time codes, each behind a policy.
-
Each app reads only its own paths
Pods, VMs and pipelines prove who they are, then read what their policy allows.
-
Every request is logged
Allowed and denied calls land in the audit log, ready for your SIEM.
-
Hardened at runtime
AccuKnox CWPP protects every Secrets Manager pod with KubeArmor.
A separate product from the AccuKnox CNAPP platform
Secrets Manager ships and installs on its own. You do not need an AccuKnox CNAPP subscription to run it. Contact your AccuKnox point of contact for the Helm chart.
Deploy and Run Secrets Manager¶
-
See what runs where and how a request reaches a secret.
-
Install with Helm, then initialize and unseal the server.
-
Install from an internal registry with no internet access.
-
Run three nodes, take snapshots, restore, and handle Day 2 jobs.
Connect Your Applications in One of Two Ways¶
-
The app reads the secret itself and keeps it in memory. A few lines of code.
Java · .NET · Python · Node.js
-
Sync secrets into a Kubernetes secret. The app code does not change.
Not sure which one fits? See Choose a Method.
Follow a Use Case¶
-
Sync a Database Password Into a Kubernetes App
WordPress reads its MySQL password from Secrets Manager. Includes a video.
-
Store Secrets in the KV Engine
Create, read, version, and delete a secret in the UI.
-
Encrypt and decrypt values with the Transit engine.
-
Generate and validate 6-digit MFA codes under policy control.
-
Share Secrets in an Organisation
Give each teammate a scoped account that reads only what they need.
-
Answers to the questions customers ask most often.