Getting Started
Connect your CyberArk Conjur appliance to DuoKey Cockpit as a secret manager.
This guide walks through connecting CyberArk Conjur to DuoKey Cockpit as a secret manager backend, so Cockpit can list, read, write, and delete secrets stored in Conjur.
Create (or identify) a Conjur host identity, such as host/dke-cockpit, and grant it policy access to the variables you want DuoKey Cockpit to manage before starting this guide. You will also need that identity's API key.
Prepare a Conjur identity
In your Conjur policy, declare (or reuse) a host identity that DuoKey Cockpit will authenticate as, for example host/dke-cockpit, and grant it access to the variables Cockpit should be able to read, write, list, or delete. Retrieve the API key for that identity from Conjur.
Open Secret Managers in DuoKey Cockpit
- Log in to DuoKey Cockpit.
- In the left navigation, go to Admin > Secret Managers.
- Click Add and select CyberArk Conjur from the list of supported providers.
Enter the connection details
Fill in the connection form:
| Field | Value |
|---|---|
| App Name | A label for this connection, e.g. `CyberArk Conjur - Production`. |
| Conjur Appliance URL | https://conjur.internal.corp |
| Account | The Conjur account (organization) name, e.g. myorg. |
| Login | The host identity created in Step 1, e.g. host/dke-cockpit. |
| API Key | The API key for that identity. |
| CA Certificate | Optional - paste a PEM certificate if your appliance uses a self-signed or private CA. |
| Verify SSL | Leave enabled unless connecting to a trusted lab/test appliance without a valid certificate. |
Test the connection
Click Test Connection. DuoKey Cockpit authenticates against Conjur using the account, login, and API key you provided and reports whether the connection is healthy. Resolve any errors (see Troubleshooting) before continuing.
Save the connection
Click Save. The connection now appears in Admin > Secret Managers, and DuoKey Cockpit users with the appropriate permissions can list, read, write, and delete secrets stored under this Conjur connection.
Verify in Cockpit
- Open the new connection from the Secret Managers list.
- Confirm the status shows as healthy.
- List secrets to confirm the configured identity can see the variables expected from Step 1.
Troubleshooting
Connection test fails with an authentication error
- Confirm the Account and Login values exactly match the Conjur identity (e.g.
host/dke-cockpit, not justdke-cockpit). - Confirm the API Key was copied without extra whitespace and has not been rotated in Conjur since it was copied.
Connection test fails with a TLS/certificate error
- If the appliance uses a self-signed or internal CA, paste the CA certificate (PEM) into the CA Certificate field.
- Only disable Verify SSL for trusted lab or test appliances - never in production.
Connection succeeds but no secrets are visible
- The configured Conjur identity likely does not have policy access to the variables you expect. Review the identity's permissions in Conjur policy.
Getting Help
If you encounter issues not covered here:
- Review the connection's status and last health check result in Admin > Secret Managers.
- Contact support:
- Email: [email protected]
- Include: connection name, error message, and (if relevant) the Conjur appliance version.
Next Steps
- Review Overview for how the integration works and its security considerations.
- Plan Conjur policy scoping so the DuoKey Cockpit identity only has access to the variables it needs.