Repository navigation
Add IncludeChain store property for AWSSMPEM, Documentation updates - #9
Merged
Merged
Conversation
Adds an optional IncludeChain store-type property (default false) that writes the issuer chain into the single concatenated PEM secret (leaf, then chain leaf-first, then private key). Ignored when SeparatePrivateKey is enabled, since the JSON format already includes the chain. A missing property reads as false, so existing stores are unchanged after upgrade. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Inventory calls BatchGetSecretValue and management operations call DescribeSecret; both fail without these IAM actions but they were not listed in the documentation. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Adds UntagResource, ReplicateSecretToRegions, and RemoveRegionsFromReplication (called when using tags or replica regions) and fixes the action names to the secretsmanager:<Action> form so they can be pasted directly into an IAM policy. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
UpdateSecretTagsAsync computed the tag keys that overlap with the new tags but then untagged every existing tag on the secret whenever any key overlapped, wiping tags not managed by Keyfactor. Only the overlapping keys are now removed before re-tagging; other tags are kept. Also adds the .NET 10 target to the changelog. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
When an AWSSMPEM secret failed to parse during inventory, the full secret value (including the unencrypted private key) was logged at the Warning level. The warning now contains only the secret name and the parse error; the malformed warning message is also fixed. The raw store properties trace now redacts Secret-type fields (OAuth client ID/secret, IAM user access key/secret). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
update to v5
indrora
added a commit
that referenced
this pull request
Oct 6, 2026
* Add IncludeChain store property for AWSSMPEM, Documentation updates (#9) * Add IncludeChain store property for AWSSMPEM Adds an optional IncludeChain store-type property (default false) that writes the issuer chain into the single concatenated PEM secret (leaf, then chain leaf-first, then private key). Ignored when SeparatePrivateKey is enabled, since the JSON format already includes the chain. A missing property reads as false, so existing stores are unchanged after upgrade. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs: add BatchGetSecretValue and DescribeSecret to required permissions Inventory calls BatchGetSecretValue and management operations call DescribeSecret; both fail without these IAM actions but they were not listed in the documentation. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs: complete and correct the IAM permissions list Adds UntagResource, ReplicateSecretToRegions, and RemoveRegionsFromReplication (called when using tags or replica regions) and fixes the action names to the secretsmanager:<Action> form so they can be pasted directly into an IAM policy. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Add net10.0 target framework Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Only untag overlapping keys when updating secret tags UpdateSecretTagsAsync computed the tag keys that overlap with the new tags but then untagged every existing tag on the secret whenever any key overlapped, wiping tags not managed by Keyfactor. Only the overlapping keys are now removed before re-tagging; other tags are kept. Also adds the .NET 10 target to the changelog. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Stop logging secret contents and credentials When an AWSSMPEM secret failed to parse during inventory, the full secret value (including the unencrypted private key) was logged at the Warning level. The warning now contains only the secret name and the parse error; the malformed warning message is also fixed. The raw store properties trace now redacts Secret-type fields (OAuth client ID/secret, IAM user access key/secret). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Update generated docs * Update keyfactor-release-workflow.yml update to v5 * Update keyfactor-release-workflow.yml * docs: auto-generate README and documentation [skip ci] --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io> Co-authored-by: Morgan Gangwere <470584+indrora@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * Update integration-manifest.json (#10) * docs: auto-generate README and documentation [skip ci] --------- Co-authored-by: Joe VanWanzeele <76071503+joevanwanzeeleKF@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Added "IncludeChain" property, that conditionally depends on "SeparatePrivateKey" to indicate that the full chain should be included in the cert secret.
Updated documentation to include full list of required permissions. Cleaned up formatting.