diff --git a/faq/secret-manager.mdx b/faq/secret-manager.mdx index eb958957a7..a61e15aaa7 100644 --- a/faq/secret-manager.mdx +++ b/faq/secret-manager.mdx @@ -5,7 +5,7 @@ meta: content: h1: Secret Manager dates: - validation: 2024-09-23 + validation: 2025-03-27 category: identity-and-access-management productIcon: SecretManagerProductIcon --- @@ -40,3 +40,5 @@ To understand the secrets encryption process, refer to our [related documentatio At the end of the month, you are billed for the number of secret versions stored and API requests made on the service. A secret version is billed if it is in an enabled or disabled state. If, for example, you have used a secret version for five days, you will only be billed for the five days and not for the whole month. Find out more about pricing on our [dedicated page](https://www.scaleway.com/en/pricing/?tags=available). + +Recovering secrets [scheduled for deletion](/secret-manager/concepts/#scheduled-deletion) is billed €0.01 per version associated with the secret. diff --git a/menu/navigation.json b/menu/navigation.json index 04afc14b5a..626b4ee65d 100644 --- a/menu/navigation.json +++ b/menu/navigation.json @@ -555,6 +555,10 @@ "label": "Delete a secret", "slug": "delete-secret" }, + { + "label": "Recover secrets scheduled for deletion", + "slug": "recover-secrets" + }, { "label": "Delete a version", "slug": "delete-version" diff --git a/pages/secret-manager/concepts.mdx b/pages/secret-manager/concepts.mdx index 7b2fb3b61e..39b874f3a8 100644 --- a/pages/secret-manager/concepts.mdx +++ b/pages/secret-manager/concepts.mdx @@ -7,7 +7,7 @@ content: paragraph: Discover essential concepts of Scaleway Secret Manager, including secret versioning, ephemeral policies, and path management. tags: secret-manager secret version dates: - validation: 2025-01-13 + validation: 2025-03-27 --- ## Disabling a version @@ -109,6 +109,14 @@ Secret types refer to the different kinds of sensitive data you can store with S Upon secret creation, you must choose a secret type that will also be applied to the secret version. All the secret's subsequent versions must be of the same type. +## Scheduled deletion + +Scheduled deletion lets you mark a secret and its versions for deletion ahead of time. Instead of immediate deletion, the secret enters a 7-day pending deletion period, during which you can still [recover it](/secret-manager/how-to/recover-secrets/). + +During this time, you can read secret versions but cannot edit, access, or delete them. After the retention period, the secret and all its versions are permanently deleted. You can also schedule a secret version for deletion without impacting the secret associated with the version. + +Recovering deleted secrets is billed €0.01 per version associated with the secret. + ## Tag Tags allow you to organize your secrets. This gives you the possibility of sorting and filtering your secrets in any organizational pattern of your choice, which in turn helps you arrange, control, and monitor your secrets. diff --git a/pages/secret-manager/how-to/delete-secret.mdx b/pages/secret-manager/how-to/delete-secret.mdx index 738f2581a7..5d6951053c 100644 --- a/pages/secret-manager/how-to/delete-secret.mdx +++ b/pages/secret-manager/how-to/delete-secret.mdx @@ -5,15 +5,17 @@ meta: content: h1: How to delete a secret paragraph: Discover how to securely delete secrets using Scaleway's intuitive console. Follow these steps to manage your sensitive data effectively. -tags: secret sensitive-data storage-system +tags: secret sensitive-data storage-system schedule-deletion dates: - validation: 2025-03-14 + validation: 2025-03-27 posted: 2023-02-21 categories: - identity-and-access-management --- -This page explains how to delete a [secret](/secret-manager/concepts/#secret) using the [Scaleway console](https://console.scaleway.com). You **cannot delete protected secrets**, i.e. secrets to which you have applied [secret protection](/secret-manager/concepts/#secret-protection). +This page explains how to [schedule secret deletion](/secret-manager/concepts/#scheduled-deletion) using the [Scaleway console](https://console.scaleway.com). You **cannot delete protected secrets**, i.e. secrets to which you have applied [secret protection](/secret-manager/concepts/#secret-protection). + +Once you schedule a secret for deletion, it enters a 7 day pending deletion period, during which you can still [recover it](/secret-manager/how-to/recover-secrets/). After this retention period, the secret and all its versions are permanently deleted. @@ -25,13 +27,14 @@ This page explains how to delete a [secret](/secret-manager/concepts/#secret) us 1. Click **Secret Manager** in the **Security and Identity** section of the [Scaleway console](https://console.scaleway.com/) side menu. 2. Select the [region](/secret-manager/concepts/#region) in which to delete the secret, in the **Region** drop-down. -3. Access the secret you wish to delete. The secret's **Overview** tab displays. -4. Scroll down and click **Delete secret**. A pop-up displays. -5. Type **DELETE** and click **Delete secret**. +3. Click next to the secret you want to delete and click **Delete**. A pop-up displays informing you that the action schedules the deletion of your secret and its version. +4. Type **DELETE** and click **Delete secret** to confirm. Your secret displays in the **Scheduled for deletion** tab for a period of 7 days before being permanently deleted. - - Although you cannot delete a [protected secret](/secret-manager/concepts/#secret-protection), you can delete its versions - - Deleting a secret is a permanent action. It erases every version you have created for your secret + - Although you cannot delete a [protected secret](/secret-manager/concepts/#secret-protection), you can delete its versions. + - Deleting a secret is a permanent action. It erases every version you have created for your secret if you do not [recover it](/secret-manager/how-to/recover-secrets/) before the end of the retention period. + - Scheduled deletion does not delete your secret immediately unless it is an ephemeral secret. [Find out how to recover secrets scheduled for deletion](/secret-manager/how-to/recover-secrets/). + diff --git a/pages/secret-manager/how-to/delete-version.mdx b/pages/secret-manager/how-to/delete-version.mdx index 67eb94df2e..3cda39c966 100644 --- a/pages/secret-manager/how-to/delete-version.mdx +++ b/pages/secret-manager/how-to/delete-version.mdx @@ -5,15 +5,15 @@ meta: content: h1: How to delete a version paragraph: Learn how to securely delete versions of secrets using the Scaleway console. Follow these steps to effectively manage your sensitive data. -tags: sensitive-data storage-system api-key +tags: sensitive-data storage-system api-key schedule-deletion dates: - validation: 2025-03-14 + validation: 2025-03-27 posted: 2023-02-21 categories: - identity-and-access-management --- -This page explains how to delete a secret [version](/secret-manager/concepts/#version) using the [Scaleway console](https://console.scaleway.com). +This page explains how to [schedule a secret for deletion](/secret-manager/concepts/#scheduled-deletion) using the [Scaleway console](https://console.scaleway.com). @@ -26,12 +26,11 @@ This page explains how to delete a secret [version](/secret-manager/concepts/#ve 2. Select the [region](/secret-manager/concepts/#region) in which to delete the version, in the **Region** drop-down. 3. Access the secret for which you want to delete the version. Your secret's **Overview** tab displays. 4. Click the **Versions** tab. -5. Click next to the version you want to delete. -6. Click **Delete**. A pop-up displays. -7. Type **DELETE** and click **Delete version**. +5. Click next to the version you want to delete, and click **Delete**. A pop-up displays informing you that the action schedules the deletion of your version. +6. Type **DELETE** and click **Delete version** to confirm. Your version displays in the **Scheduled for deletion** tab for a period of 7 days before being permanently deleted. - Deleting a version is permanent. You will not be able to use the version again. + Deleting a version is permanent. You will not be able to use the version again if you do not [recover it](/secret-manager/how-to/recover-secrets/) before the end of the 7-day retention period. diff --git a/pages/secret-manager/how-to/recover-secrets.mdx b/pages/secret-manager/how-to/recover-secrets.mdx new file mode 100644 index 0000000000..df524dfd6a --- /dev/null +++ b/pages/secret-manager/how-to/recover-secrets.mdx @@ -0,0 +1,38 @@ +--- +meta: + title: How to recover secrets scheduled for deletion + description: Discover how to securely delete secrets using the Scaleway console. Follow these steps to manage your sensitive data effectively. +content: + h1: How to recover secrets scheduled for deletion + paragraph: Discover how to securely delete secrets using Scaleway's intuitive console. Follow these steps to manage your sensitive data effectively. +tags: secret sensitive-data scheduled-deletion recover-secret +dates: + validation: 2025-03-27 + posted: 2025-03-27 +categories: + - identity-and-access-management +--- + +This page shows you how to recover secrets scheduled for deletion using the Scaleway [console](https://console.scaleway.com). Once you schedule a secret for deletion, it enters a 7 day pending deletion period, during which you can still recover it. +After this retention period, the secret and all its versions are permanently deleted. + + + Scheduled deletion deletes ephemeral secrets and their versions immediately + + + + +- A Scaleway account logged into the [console](https://console.scaleway.com) +- [Owner](/iam/concepts/#owner) status or [IAM permissions](/iam/concepts/#permission) allowing you to perform actions in the intended Organization +- [Generated an API key](/iam/how-to/create-api-keys/) and enabled the `SecretManagerFullAccess` [permission set](/iam/reference-content/permission-sets/) +- Created a [secret](/secret-manager/how-to/create-secret/) +- Scheduled secrets for deletion + +1. Click **Secret Manager** in the **Security and Identity** section of the [Scaleway console](https://console.scaleway.com/) side menu. +2. Select the [region](/secret-manager/concepts/#region) in which to recover the secret, in the **Region** drop-down. +3. Click the **Scheduled for deletion** tab. Your secrets dispaly. +4. Click next to the secret you want to recover and click **Recover**. A pop-up displays with the estimated cost for recovering the secret. + + Recovering a secret is billed €0.01 per version associated with the secret + +5. Click **Recover secret** to confirm. Your secret displays in the **Secrets** tab. \ No newline at end of file