DuoKey for CyberArk Conjur
Connect CyberArk Conjur to DuoKey Cockpit as a secret manager backend.
Introduction
CyberArk Conjur is CyberArk's secrets-management engine. DuoKey Cockpit can connect to a Conjur appliance as one of several supported secret manager backends, letting Cockpit centrally list, read, write, and delete secrets that are stored and governed in Conjur.
What is CyberArk Conjur?
In Conjur, secrets are modelled as variables that are declared through policy and whose values are read and written through Conjur's API. Access to those variables is mediated by role-based policy and a short-lived, per-request access token, so Cockpit never holds a long-lived session against your Conjur appliance.
Integration Benefits
Centralized Secret Access
List, read, write, and delete secrets stored in Conjur directly from DuoKey Cockpit.
Policy-Governed
Secret access follows Conjur's own role-based policy model - Cockpit authenticates as a configured identity, it does not bypass Conjur's authorization.
Short-Lived Tokens
Cockpit re-authenticates for each operation using your configured account, login, and API key, rather than holding a long-lived session token.
Complete Audit Trail
Secret manager connections and secret operations are recorded in DuoKey Cockpit's audit log.
How It Works
DuoKey Cockpit authenticates to CyberArk Conjur over HTTPS and operates on secrets (variables) governed by Conjur policy.
- An administrator adds a CyberArk Conjur connection in DuoKey Cockpit under Secret Managers, supplying the Conjur appliance URL, account, login identity, and API key.
- Cockpit authenticates against the configured identity to obtain a short-lived access token.
- Using that token, Cockpit can list, read, write, or delete secrets that exist as variables in Conjur, subject to the permissions granted to the configured identity by Conjur policy.
- Every connection test and secret operation is recorded in the Cockpit audit log.
Configuration Fields
When you add a CyberArk Conjur secret manager in Cockpit (Admin > Secret Managers > Add > CyberArk Conjur), you provide:
| Field | Description |
|---|---|
| App Name | A label for this connection inside DuoKey Cockpit. |
| Conjur Appliance URL | https://conjur.internal.corp |
| Account | The Conjur account (organization) name, e.g. myorg. |
| Login | The identity Cockpit authenticates as, e.g. host/dke-cockpit. |
| API Key | The API key for the configured login identity. |
| CA Certificate | Optional PEM certificate for appliances using a self-signed or private CA. |
| Verify SSL | Whether Cockpit validates the appliance TLS certificate. Enabled by default; only disable for trusted lab/test appliances. |
Use the Test Connection action in the wizard to verify the account, login, and API key against your Conjur appliance before saving the connection.
Prerequisites
Prerequisites
- A reachable CyberArk Conjur appliance (Open Source, Enterprise, or Conjur Cloud)
- A Conjur identity (e.g. a host identity such as
host/dke-cockpit) with policy granting it access to the variables Cockpit should manage - The API key for that identity
- Network connectivity (HTTPS) from DuoKey Cockpit to the Conjur appliance
- DuoKey Cockpit account with permission to manage Secret Managers
Use Cases
Centralized Secret Governance
Keep secrets under Conjur's existing policy model while giving DuoKey Cockpit administrators a single place to inspect and manage them.
Hybrid Secret Estates
Combine a Conjur connection with other supported secret manager backends (HashiCorp Vault, OpenBao, Azure Key Vault, AWS Secrets Manager, GCP Secret Manager) under one Cockpit view.
Self-Signed / On-Prem Appliances
Connect to on-premises Conjur appliances using a custom CA certificate, common for internal deployments.
Compliance & Audit
Track who added, tested, or used a Conjur connection through DuoKey Cockpit's audit trail.
Security Considerations
- Cockpit re-authenticates to Conjur for every operation rather than caching a long-lived session, limiting the exposure window of an access token.
- TLS certificate validation is enabled by default; disabling it (or pinning a custom CA) should be reserved for appliances that cannot present a publicly trusted certificate.
- The configured API key is stored encrypted by DuoKey Cockpit and is never displayed again after it is saved - rotate it in Conjur and update the Cockpit connection if it needs to change.
- Access is bounded by whatever policy Conjur grants to the configured login identity - scope that identity to only the variables Cockpit needs.
Support
For technical support or questions about the DuoKey CyberArk Conjur integration:
- Email: [email protected]
- Documentation: DuoKey Support
- Status: status.duokey.com
Our integration specialists are available to help you plan a CyberArk Conjur secret manager connection for your organization. Contact us for assistance.