tencent cloud

Secrets Manager

Overview

Unduh
Mode fokus
Ukuran font
Terakhir diperbarui: 2026-09-08 17:04:10
Diterjemahkan oleh AI
Currently, account passwords for cloud products are subject to issues such as improper access management, infrequent password rotation, and plaintext keys in configurations. These issues lead to digital asset loss. To address these risks, Database Credentials periodically rotate credentials, automatically generate strong passwords, and manage sensitive configuration information. This reduces account risks and security threats while also enhancing the security of business data.

Main Features

SSM integrates with the console and takes over the feature for applying for and distributing database accounts.
Configure encryption protection for sensitive information by using KMS.
SSM automatically generates strong passwords and periodically modifies and rotates them.
Flexibly set the period for automatic rotation.

Product Architecture





Process Description

1. The administrator creates a database instance and sets up the database account and password.
2. The administrator creates a database credential object in SSM.
Grant SSM access to the MySQL management service.
Set the database username prefix and other related items.
Configure a policy for automatic rotation.
3. When the application system needs to access the database, you can request access credentials from SSM. For details about the API request, see Obtain Credential Plaintext.
4. The application system accesses the target database for the corresponding user by calling the credential API, parsing the returned content to obtain the plaintext credentials, and retrieving the account and password.

Use Limits

Automatic credential rotation currently supports TencentDB for MySQL, TDSQL-C for MySQL, PostgreSQL, SQL Server, TDSQL-MySQL, and MongoDB.

Usage Instructions

Bantuan dan Dukungan

Apakah halaman ini membantu?

masukan