Sync Command

Synchronizes selected keys from Keeper Vault to an external secrets manager

sync command

Description: Import and synchronize secrets from the Keeper Vault with external secrets management systems

ksm sync --credentials <UID> --type [aws|azure|gcp|json] [--dry-run] [--preserve-missing] --map <KEY NOTATION>...

Requires a Secrets Manager profile that has been initialized with: ksm profile init <TOKEN> See the Profile Documentation for more information

parameters:

  • -t, --type Type of the target key/value storage. Available types are:

    • aws - AWS Secrets Manager

    • azure- Azure Key Vault

    • gcp - GCP Secret Manager

    • json - lists all pending sync operations including both source and destination values

  • -m, --map <KEY NOTATION> Map destination key names to values using notation URI

  • -c, --credentials <uid> UID of Keeper record with credentials to access destination key/value storage. The specified record must be shared with the Keeper Secrets Manager Application

optional parameters:

  • -n, --dry-run Perform a trial run with no changes made.

  • -p, --preserve-missing Preserve destination value when source value is deleted.

AWS-Specific Options

--record, -r <RECORD> Sync individual records by title or UID. Can be specified multiple times. --folder, -f <FOLDER> Sync all records from specified folder(s) - non-recursive. --folder-recursive, -fr <FODLER> Sync all records from specified folder(s) and all subfolders recursively. --raw-json, -rj Store full raw JSON in KMS secret (same format as secret get <UID> --json).

Automation with Crontab

You can automate secret synchronization using cron jobs.

Example 1: Simple Daily Sync

Sync once per day at 2 AM:

Example 2: Complex Multi-Sync Script

For multiple sync operations with different mappings, create a shell script:

Create /home/user/scripts/ksm-sync-all.sh:

Make the script executable:

Add to crontab to run every 6 hours:

Sync Types

Select an external provider below to learn more about the integration.

AWS Secrets Manager SyncAzure Key Vault SyncGoogle Cloud Secret Manager Sync

Last updated

Was this helpful?