Skip to content

Secret Managers

For production deployments, a cloud secret manager is recommended for storing sensitive values such as passwords, keys, and tokens. If a secret manager is not configured (SECRET_MANAGER=false), the deployment script reads sensitive values directly from the .env file instead.

The supported providers are AWS Secrets Manager, Google Secret Manager, Azure Key Vault, and HashiCorp Vault.

ProviderNamingExample
AWS<prefix>/KEYkmi/MONGO_PASSWORD
GCP / Azure / Vault<prefix>-KEYkmi-MONGO_PASSWORD

The prefix is set via SECRET_PREFIX (default kmi).

Create the following secrets in your chosen provider:

Secret KeyDescription
MONGO_USERNAMEMongoDB root username
MONGO_PASSWORDMongoDB root password
ADMIN_PASSWORDKMI admin user password
JWT_SECRETJWT signing secret (16 bytes hex)
AES_KEYAES encryption key (32 bytes hex)
OIDC_CLIENT_SECRETOIDC client secret (only if OIDC_ENABLED=true)

Configuration in .env:

Terminal window
SECRET_MANAGER=aws
SECRET_PREFIX=kmi
SECRET_REGION=us-west-2

Create the required secrets:

Terminal window
aws secretsmanager create-secret --name kmi/MONGO_USERNAME --secret-string "your_username"
aws secretsmanager create-secret --name kmi/MONGO_PASSWORD --secret-string "your_password"
aws secretsmanager create-secret --name kmi/ADMIN_PASSWORD --secret-string "your_admin_password"
aws secretsmanager create-secret --name kmi/JWT_SECRET --secret-string "your_jwt_secret"
aws secretsmanager create-secret --name kmi/AES_KEY --secret-string "your_aes_key"
# If OIDC enabled:
aws secretsmanager create-secret --name kmi/OIDC_CLIENT_SECRET --secret-string "your_oidc_client_secret"

To generate the JWT_SECRET and AES_KEY values before storing them:

Terminal window
# Generate JWT secret (16 bytes hex)
openssl rand -hex 16
# Generate AES key (32 bytes hex)
openssl rand -hex 32