ncloud_secret_create_secret
Create a Naver Cloud Secret Manager secret from JSON key/value pairs. Set rotation targets and use dryRun=true to preview before creation.
Instructions
Create a secret. secretValue is a JSON object string of 1-100 key/value pairs (≤10,000 bytes); rotationTargets names the keys that rotation replaces. Use dryRun=true to preview.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| memo | No | Description (0-1000 bytes) | |
| dryRun | No | If true, returns a preview without creating | |
| kmsKeyTag | No | KMS key tag (see ncloud_secret_list_protection_keys) — required when protectionKeyType=USER_MANAGED_KEY | |
| triggerId | No | Rotation trigger ID (see ncloud_secret_list_triggers) — required when autoRotationYN=Y | |
| secretName | Yes | Secret name (3-15 chars: letters, digits, '-', '_'; starts with a letter) | |
| secretType | No | Secret type (BASIC is the only valid value) | BASIC |
| secretValue | Yes | Secret value as a JSON object string, e.g. '{"password":"..."}' (1-100 key/value pairs, ≤10,000 bytes) | |
| keyIsolation | No | Which Secret Manager host to call: 'global' (default) for secrets encrypted with a KMS global key (secretmanager.apigw.ntruss.com); 'regional' for secrets encrypted with a KMS region-isolated key (ocapi-kr.ncloud.com/secretmanager — the only option in the JPN region) | global |
| autoRotationYN | No | Enable automatic rotation (Y) or not (N, default) | N |
| kmsBoundaryType | No | KMS key isolation: GLOBAL or ISOLATED (new keys support ISOLATED only) | |
| rotationTargets | Yes | Keys of secretValue that rotation replaces (at least one) | |
| protectionKeyType | No | Protection key: DEFAULT (service key) or USER_MANAGED_KEY (your KMS key) | DEFAULT |
| autoRotationPeriod | No | Rotation period in days (1-730, default 90) — required when autoRotationYN=Y |