tencent cloud

Secrets Manager

Overview

下载
聚焦模式
字号
最后更新时间: 2026-09-08 17:04:10
本文档由 AI 翻译
Currently, account passwords for cloud products are subject to issues such as improper access management, infrequent password rotation, and plaintext keys in configurations. These issues lead to digital asset loss. To address these risks, Database Credentials periodically rotate credentials, automatically generate strong passwords, and manage sensitive configuration information. This reduces account risks and security threats while also enhancing the security of business data.

Main Features

SSM integrates with the console and takes over the feature for applying for and distributing database accounts.
Configure encryption protection for sensitive information by using KMS.
SSM automatically generates strong passwords and periodically modifies and rotates them.
Flexibly set the period for automatic rotation.

Product Architecture





Process Description

1. The administrator creates a database instance and sets up the database account and password.
2. The administrator creates a database credential object in SSM.
Grant SSM access to the MySQL management service.
Set the database username prefix and other related items.
Configure a policy for automatic rotation.
3. When the application system needs to access the database, you can request access credentials from SSM. For details about the API request, see Obtain Credential Plaintext.
4. The application system accesses the target database for the corresponding user by calling the credential API, parsing the returned content to obtain the plaintext credentials, and retrieving the account and password.

Use Limits

Automatic credential rotation currently supports TencentDB for MySQL, TDSQL-C for MySQL, PostgreSQL, SQL Server, TDSQL-MySQL, and MongoDB.

Usage Instructions

帮助和支持

本页内容是否解决了您的问题?

填写满意度调查问卷,共创更好文档体验。

文档反馈