Skip to main content
Version: Release 26.3

Conjur Plugin

The Conjur Plugin (Jython-based) integrates Digital.ai Release with CyberArk Conjur. It retrieves secrets from a Conjur server at runtime and stores them in password-type release variables, which later tasks in the release can then use.

This plugin runs directly on the Release server. It works with both self-hosted Conjur and CyberArk Conjur Cloud (SaaS), and supports and supports basic and OAuth 2.0 authentication methods.

note

For scalable, runner-based execution, use the Conjur Container Plugin.

important

You must set up a connection to a Conjur server before external secrets can be configured.

What You Can Do With This Plugin​

  • Retrieve secrets from a CyberArk Conjur server (self-hosted or SaaS)
  • Populate password-type release variables with secrets for use by later tasks
  • Authenticate to Conjur using basic or OAuth 2.0 methods

Prerequisites​

The plugin requires the following:

  • A running CyberArk Conjur server (self-hosted or Conjur Cloud) reachable over HTTP(S).
  • A Conjur account name that holds the secrets you want to retrieve.
  • Credentials for the authentication method you plan to use (for example, a username and password for basic authentication, or the client ID, client secret, and access token URL for OAuth 2.0).
  • Policy permissions that allow the authenticating identity to read the required secrets.

Set up a Connection to the Conjur Server​

  1. From the navigation pane, click Configuration > Connections.
  2. Under Secrets management, beside Conjur: Server, click Add button.
  3. Provide the connection details:
    Field NameDescription
    Title*Symbolic name for the configuration. This name displays in Conjur tasks.
    URL*Address where the server can be reached, in the form http(s)://address:port. For CyberArk Conjur Cloud (SaaS), suffix the base URL with /api (for example, <BASE_URL>/api).
    Account*Name of the Conjur account holding the secret.
    Authentication method*The method used to authenticate with the Conjur server. See Authentication Methods.
  4. To test the connection, click Test.
  5. To save the configuration, click Save.

Conjur Server Connection Page

After the server connection is set up, you can map Conjur secrets to release variables.

Authentication Methods​

Conjur supports Basic and OAuth2 authentication methods. Select the method from the Authentication method drop-down list, then provide the fields required for that method:

  • Basic: Enter a Username and Password. Basic Method
  • OAuth2: Enter the Service ID, Access Token URL, Client ID, Client Secret, and Scope. Optionally, enable Skip TLS/SSL to bypass certificate validation. Use this method to authenticate with an OAuth 2.0 provider using an access token. OAuth Method

Get Secret​

The Get Secret task retrieves a single secret from a Conjur server and stores it in a password-type release variable. Add one Get Secret task for each secret you need, and place each task so that it runs immediately before the task that uses the secret.

Before you add the task, create a release variable to hold the secret: name the variable, set its type to Password, and clear the Required and Show on Release Form options.

Input Fields​

Conjur Release Variable Configuration

Field NameDescriptionExample
Server*The configured Conjur server connection to use.conjur.example.com
Name of secret as stored in Conjur*The name (path) of the secret as it is stored in Conjur.prod/db/password

Output Fields​

Get Secret Output Properties

Output PropertyDescription
Release Variable*The password-type release variable that stores the retrieved secret.

Example Usage​

Suppose you want to retrieve a database password stored in Conjur and use it in a later Jira task:

FieldValue
Serverconjur.example.com
Name of secret as stored in Conjurprod/db/password
Release Variable${newSecret}

After running the task, the release variable newSecret holds the retrieved secret. A following Jira Create Issue task can then use newSecret as the Jira password, overriding the password configured for the Jira server.