Deleting a secret
To delete a secret:
- In the management console
, select the folder the secret belongs to. - Go to Lockbox.
- In the left-hand menu, select Secrets.
- Next to the secret you need, click
. - In the menu that opens, select Delete.
- In the window that opens, click Delete.
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id. If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
-
View the description of the CLI command for deleting a secret:
yc lockbox secret delete --help -
Request a list of secrets:
yc lockbox secret list --cloud-id <cloud_ID> --folder-name <folder_name>Result:
+----------------------+------------------+------------+---------------------+----------------------+--------+ | ID | NAME | KMS KEY ID | CREATED AT | CURRENT VERSION ID | STATUS | +----------------------+------------------+------------+---------------------+----------------------+--------+ | e6q942hj2r5n******** | <secret_1_name> | | 2021-11-09 13:07:12 | e2r9pdm39tn2******** | ACTIVE | | e4qkyo469mu2******** | <secret_2_name> | | 2021-12-09 06:50:37 | e6fpq386othp******** | ACTIVE | +----------------------+------------------+------------+---------------------+----------------------+--------+ -
To delete a secret, run the command:
yc lockbox secret delete --id e4qkyo469mu2********Result:
id: e4qkyo469mu2******** folder_id: b1ulgko2th57******** created_at: "2021-11-08T17:13:48.393Z" ... status: ACTIVE payload_entry_keys: - <key> -
Make sure the secret is not in the list:
yc lockbox secret list --cloud-id <cloud_ID> --folder-name <folder_name>Result:
+----------------------+-----------------+------------+---------------------+----------------------+--------+ | ID | NAME | KMS KEY ID | CREATED AT | CURRENT VERSION ID | STATUS | +----------------------+-----------------+------------+---------------------+----------------------+--------+ | e6q942hj2r5n******** | <secret_1_name> | | 2021-11-09 13:07:12 | e2r9pdm39tn2******** | ACTIVE | +----------------------+-----------------+------------+---------------------+----------------------+--------+
If you do not have Terraform yet, install it and configure the Yandex Cloud provider.
-
Open the Terraform configuration file and delete the part with the secret description:
Sample secret description in the Terraform configuration
... resource "yandex_lockbox_secret" "my_secret" { name = "My secret" description = "test secret from tf" folder_id = "b1gmitvfx321d3********" kms_key_id = "abjp8q2fjfg0s********" deletion_protection = true labels = { tf-label = "tf-label-value", empty-label = "" } } ... -
Apply the changes:
-
In the terminal, navigate to the configuration file directory.
-
Make sure the configuration is correct using this command:
terraform validateIf the configuration is valid, you will get this message:
Success! The configuration is valid. -
Run this command:
terraform planYou will see a list of resources and their properties. No changes will be made at this step. Terraform will show any errors in the configuration.
-
Apply the configuration changes:
terraform apply -
Type
yesand press Enter to confirm the changes.
-
You can check the secret deletion using the management console
yc lockbox secret list
To delete a secret, use the delete REST API method for the Secret resource or the SecretService/Delete gRPC API call.