Skip to content

feat(conjur): add CyberArk Conjur provider - #15

Merged
bonifaido merged 3 commits into
mainfrom
feat/conjur
Sep 28, 2026
Merged

bonifaido merged 3 commits into
mainfrom
feat/conjur

Conversation

@bonifaido

@bonifaido bonifaido commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Adds a conjur provider for CyberArk Conjur (Secrets Manager Self-Hosted and SaaS). It exchanges the identity JWT for a Conjur access token through the JWT authenticator. Then it reads the configured variables in one batch request, so a rotated pair is never returned half updated, and polls for rotated values. The constructor takes a TLS config for self-hosted instances behind a private CA.

credential.VaultSecret is now an alias of a new generic credential.Secret, so Conjur results reuse the control plane's existing Vault typing. Existing consumers compile unchanged.

https://docs.cyberark.com/secrets-manager-sh/latest/en/content/developer/conjur-api-go.html

Logs in with Conjur's JWT authenticator and reads the configured variables
in one batch request, polling for rotated values. Adds a generic
credential.Secret type; VaultSecret is now an alias for it so both
providers return the same key/value result.
@bonifaido bonifaido self-assigned this Sep 28, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Address zero-expiry token handling and qualified Conjur variable ID normalization.

Review effort: Lite
Findings: None

What changed in this PR

Adds a CyberArk Conjur provider with JWT authentication, batched secret retrieval, rotation polling, TLS support, and shared secret typing.

Changes:

  • Adds Conjur configuration, authentication, retrieval, polling, telemetry, and tests.
  • Introduces credential.Secret with backward-compatible VaultSecret alias.
  • Documents Conjur usage in the README.
File Description
README.md Documents Conjur usage and configuration.
pkg/​credential/​result.go Adds the shared Secret type.
pkg/​credential/​equal.go Updates secret equality handling.
pkg/​conjur/​telemetry.go Defines Conjur telemetry attributes.
pkg/​conjur/​option.go Adds Conjur configuration options.
pkg/​conjur/​creds.go Implements authentication, retrieval, polling, and TLS support.
pkg/​conjur/​conjur_test.go Tests Conjur provider behavior.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@bonifaido
bonifaido marked this pull request as ready for review September 28, 2026 10:52
@bonifaido
bonifaido merged commit 819f174 into main Sep 28, 2026
1 check passed
@bonifaido
bonifaido deleted the feat/conjur branch September 28, 2026 10:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants