Try it
This stores a secret, injects it as a bearer token on requests tohttpbin.org, and asks httpbin to echo the request back. Save the policy as
demo.json:
demo.json
Output
curl inside the Sailbox never saw the token. Only the request that
httpbin received included it.
The same flow from the SDKs, with a GitHub token:
Secrets
A secret is a named value that belongs to your organization._, and -, up to
128 characters. A value is one non-empty line of text up to 64 KiB, with no tabs, line
breaks, or other control characters.
Policies
A credential is added by a rule in an egress policy. The rule specifies the host, optionally narrows the requests it applies to, and sets a header or query parameter to${secrets.NAME}. The
reference has the full document
format.
- Only a saved policy may reference a secret, and the secret must exist before the policy is saved. A document passed straight to a Sailbox cannot use one.
- Use an exact host. A wildcard such as
*.example.comsends the credential to every host it matches.
allowlist, so one policy limits a Sailbox
to the hosts it needs and adds their credentials. A saved policy’s document
cannot be edited. To rotate which hosts get a credential, save a new policy
and set it. To rotate the credential itself, set the secret again.
Giving a Sailbox the policy
Give the same saved policy to as many Sailboxes as you like.Where secrets live
Secrets are stored by Sail and added as the request leaves the Sailbox. Nothing inside the Sailbox ever sees the value, and no Sail API returns it:sail secret show and sail secret list print names and timestamps only.
Output
sail egress-policy list shows how many Sailboxes use each
policy and which secrets it names.