diff --git a/docs/documentation/platform/dynamic-secrets/sap-ase.mdx b/docs/documentation/platform/dynamic-secrets/sap-ase.mdx new file mode 100644 index 000000000..3b7a895fb --- /dev/null +++ b/docs/documentation/platform/dynamic-secrets/sap-ase.mdx @@ -0,0 +1,116 @@ +--- +title: "SAP ASE" +description: "Learn how to dynamically generate SAP ASE database account credentials." +--- + +The Infisical SAP ASE dynamic secret allows you to generate SAP ASE database credentials on demand. + +## Prerequisite + +- Infisical requires that you have a user in your SAP ASE instance, configured with the appropriate permissions. This user will facilitate the creation of new accounts as needed. + Ensure the user possesses privileges for creating, dropping, and granting permissions to roles for it to be able to create dynamic secrets. + The user used for authentication must have access to the `master` database. You can use the `sa` user for this purpose or create a new user with the necessary permissions. + +- The SAP ASE instance should be reachable by Infisical. + +## Set up Dynamic Secrets with SAP ASE + + + + Open the Secret Overview dashboard and select the environment in which you would like to add a dynamic secret. + + + ![Add Dynamic Secret Button](../../../images/platform/dynamic-secrets/add-dynamic-secret-button.png) + + + ![Dynamic Secret Modal](../../../images/platform/dynamic-secrets/sap-ase/dynamic-secret-sap-ase-modal.png) + + + + Name by which you want the secret to be referenced + + + + Default time-to-live for a generated secret (it is possible to modify this value when a secret is generate) + + + + The maximum time-to-live for a generated secret + + + + Your SAP ASE instance host (IP or domain) + + + + Your SAP ASE instance port. On default SAP ASE instances this is usually `5000`. + + + + The database name that you want to generate credentials for. This database must exist on the SAP ASE instance. + Please note that the user/password used for authentication must have access to this database, **and** the `master` database. + + + + Username that will be used to create dynamic secrets + + + + Password that will be used to create dynamic secrets + + + ![Dynamic Secret Setup Modal](../../../images/platform/dynamic-secrets/sap-ase/dynamic-secret-sap-ase-setup-modal.png) + + + + If you want to provide specific privileges for the generated dynamic credentials, you can modify the SQL statement to your needs. + ![Modify SQL Statements Modal](../../../images/platform/dynamic-secrets/sap-ase/dynamic-secret-sap-ase-statements.png) + + + Due to SAP ASE limitations, the attached SQL statements are not executed as a transaction. + + + + + After submitting the form, you will see a dynamic secret created in the dashboard. + + + Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials. + To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item. + Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section. + + ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png) + ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png) + + When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for. + + ![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png) + + + Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret in step 4. + + + + Once you click the `Submit` button, a new secret lease will be generated and the credentials for it will be shown to you. + + ![Provision Lease](/images/platform/dynamic-secrets/lease-values.png) + + + + +## Audit or Revoke Leases + +Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard. +This will allow you see the lease details and delete the lease ahead of its expiration time. + +![Provision Lease](/images/platform/dynamic-secrets/lease-data.png) + +## Renew Leases + +To extend the life of the generated dynamic secret lease past its initial time to live, simply click on the **Renew** as illustrated below. +![Provision Lease](/images/platform/dynamic-secrets/dynamic-secret-lease-renew.png) + + + Lease renewals cannot exceed the maximum TTL set when configuring the dynamic + secret. + diff --git a/docs/images/platform/dynamic-secrets/sap-ase/dynamic-secret-sap-ase-modal.png b/docs/images/platform/dynamic-secrets/sap-ase/dynamic-secret-sap-ase-modal.png new file mode 100644 index 000000000..2d48a93a3 Binary files /dev/null and b/docs/images/platform/dynamic-secrets/sap-ase/dynamic-secret-sap-ase-modal.png differ diff --git a/docs/images/platform/dynamic-secrets/sap-ase/dynamic-secret-sap-ase-setup-modal.png b/docs/images/platform/dynamic-secrets/sap-ase/dynamic-secret-sap-ase-setup-modal.png new file mode 100644 index 000000000..ceb474770 Binary files /dev/null and b/docs/images/platform/dynamic-secrets/sap-ase/dynamic-secret-sap-ase-setup-modal.png differ diff --git a/docs/images/platform/dynamic-secrets/sap-ase/dynamic-secret-sap-ase-statements.png b/docs/images/platform/dynamic-secrets/sap-ase/dynamic-secret-sap-ase-statements.png new file mode 100644 index 000000000..9ac56f456 Binary files /dev/null and b/docs/images/platform/dynamic-secrets/sap-ase/dynamic-secret-sap-ase-statements.png differ diff --git a/docs/mint.json b/docs/mint.json index e4e487915..bd65745c4 100644 --- a/docs/mint.json +++ b/docs/mint.json @@ -188,6 +188,7 @@ "documentation/platform/dynamic-secrets/mongo-db", "documentation/platform/dynamic-secrets/azure-entra-id", "documentation/platform/dynamic-secrets/ldap", + "documentation/platform/dynamic-secrets/sap-ase", "documentation/platform/dynamic-secrets/sap-hana", "documentation/platform/dynamic-secrets/snowflake", "documentation/platform/dynamic-secrets/totp"