diff --git a/docs/documentation/platform/dynamic-secrets/sap-hana.mdx b/docs/documentation/platform/dynamic-secrets/sap-hana.mdx new file mode 100644 index 000000000..76d79d709 --- /dev/null +++ b/docs/documentation/platform/dynamic-secrets/sap-hana.mdx @@ -0,0 +1,117 @@ +--- +title: "SAP HANA" +description: "Learn how to dynamically generate SAP HANA database account credentials." +--- + +The Infisical SAP HANA dynamic secret allows you to generate SAP HANA database credentials on demand. + +## Prerequisite + +- Infisical requires a SAP HANA database user in your instance with the necessary permissions. This user will facilitate the creation of new accounts as needed. + Ensure the user possesses privileges for creating, dropping, and granting permissions to roles for it to be able to create dynamic secrets. + +- The SAP HANA instance should be reachable by Infisical. + +## Set up Dynamic Secrets with SAP HANA + + + + Open the Secret Overview dashboard and select the environment in which you would like to add a dynamic secret. + + + ![Add Dynamic Secret Button](../../../images/platform/dynamic-secrets/add-dynamic-secret-button.png) + + + ![Dynamic Secret Modal](../../../images/platform/dynamic-secrets/dynamic-secret-modal-sap-hana.png) + + + + Name by which you want the secret to be referenced + + + + Default time-to-live for a generated secret (it is possible to modify this value when a secret is generate) + + + + Maximum time-to-live for a generated secret + + + + SAP HANA Host + + + + + SAP HANA Port + + + + Username that will be used to create dynamic secrets + + + + Password that will be used to create dynamic secrets + + + + A CA may be required for SSL if you are self-hosting SAP HANA + + + + ![Dynamic Secret Setup Modal](../../../images/platform/dynamic-secrets/dynamic-secret-setup-modal-sap-hana.png) + + + + If you want to provide specific privileges for the generated dynamic credentials, you can modify the SQL statement to your needs. + ![Modify SQL Statements Modal](../../../images/platform/dynamic-secrets/modify-sap-hana-sql-statements.png) + + + + After submitting the form, you will see a dynamic secret created in the dashboard. + + + If this step fails, you may have to add the CA certficate. + + + + + Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials. + To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item. + Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section. + + ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png) + ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png) + + When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for. + + ![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png) + + + Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret in step 4. + + + + Once you click the `Submit` button, a new secret lease will be generated and the credentials for it will be shown to you. + + ![Provision Lease](/images/platform/dynamic-secrets/lease-values.png) + + + + +## Audit or Revoke Leases + +Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard. +This will allow you see the lease details and delete the lease ahead of its expiration time. + +![Provision Lease](/images/platform/dynamic-secrets/lease-data.png) + +## Renew Leases + +To extend the life of the generated dynamic secret lease past its initial time to live, simply click on the **Renew** as illustrated below. +![Provision Lease](/images/platform/dynamic-secrets/dynamic-secret-lease-renew.png) + + + Lease renewals cannot exceed the maximum TTL set when configuring the dynamic + secret. + diff --git a/docs/images/platform/dynamic-secrets/dynamic-secret-modal-sap-hana.png b/docs/images/platform/dynamic-secrets/dynamic-secret-modal-sap-hana.png new file mode 100644 index 000000000..202431cc2 Binary files /dev/null and b/docs/images/platform/dynamic-secrets/dynamic-secret-modal-sap-hana.png differ diff --git a/docs/images/platform/dynamic-secrets/dynamic-secret-setup-modal-sap-hana.png b/docs/images/platform/dynamic-secrets/dynamic-secret-setup-modal-sap-hana.png new file mode 100644 index 000000000..1c97efe1e Binary files /dev/null and b/docs/images/platform/dynamic-secrets/dynamic-secret-setup-modal-sap-hana.png differ diff --git a/docs/images/platform/dynamic-secrets/modify-sap-hana-sql-statements.png b/docs/images/platform/dynamic-secrets/modify-sap-hana-sql-statements.png new file mode 100644 index 000000000..973fcf731 Binary files /dev/null and b/docs/images/platform/dynamic-secrets/modify-sap-hana-sql-statements.png differ diff --git a/docs/mint.json b/docs/mint.json index 33e5f5c9f..4e3049f78 100644 --- a/docs/mint.json +++ b/docs/mint.json @@ -178,7 +178,8 @@ "documentation/platform/dynamic-secrets/mongo-atlas", "documentation/platform/dynamic-secrets/mongo-db", "documentation/platform/dynamic-secrets/azure-entra-id", - "documentation/platform/dynamic-secrets/ldap" + "documentation/platform/dynamic-secrets/ldap", + "documentation/platform/dynamic-secrets/sap-hana" ] }, {