Skip to main content
Applications& internal servicesDuoKey Cockpitunified control & auditsecret managerCyberArk Conjursecrets engine
DuoKey drives CyberArk Conjur as a secret manager, so keys and secrets are managed from one console with a single audit trail.
Applies to:
CyberArk Conjur Open SourceCyberArk Conjur Enterprise / Conjur Cloud

Introduction​

CyberArk Conjur is CyberArk's secrets-management engine. DuoKey Cockpit can connect to a Conjur appliance as one of several supported secret manager backends, letting Cockpit centrally list, read, write, and delete secrets that are stored and governed in Conjur.

What is CyberArk Conjur?​

In Conjur, secrets are modelled as variables that are declared through policy and whose values are read and written through Conjur's API. Access to those variables is mediated by role-based policy and a short-lived, per-request access token, so Cockpit never holds a long-lived session against your Conjur appliance.

Integration Benefits​

Centralized Secret Access

List, read, write, and delete secrets stored in Conjur directly from DuoKey Cockpit.

Policy-Governed

Secret access follows Conjur's own role-based policy model - Cockpit authenticates as a configured identity, it does not bypass Conjur's authorization.

Short-Lived Tokens

Cockpit re-authenticates for each operation using your configured account, login, and API key, rather than holding a long-lived session token.

Complete Audit Trail

Secret manager connections and secret operations are recorded in DuoKey Cockpit's audit log.

How It Works​

Integration overview
DuoKey Cockpit
Secret Manager Connector
Configured Identityaccount / login / API key
HTTPS
CyberArk Conjur
Conjur API
Secrets (Variables)policy-governed

DuoKey Cockpit authenticates to CyberArk Conjur over HTTPS and operates on secrets (variables) governed by Conjur policy.

  1. An administrator adds a CyberArk Conjur connection in DuoKey Cockpit under Secret Managers, supplying the Conjur appliance URL, account, login identity, and API key.
  2. Cockpit authenticates against the configured identity to obtain a short-lived access token.
  3. Using that token, Cockpit can list, read, write, or delete secrets that exist as variables in Conjur, subject to the permissions granted to the configured identity by Conjur policy.
  4. Every connection test and secret operation is recorded in the Cockpit audit log.

Configuration Fields​

When you add a CyberArk Conjur secret manager in Cockpit (Admin > Secret Managers > Add > CyberArk Conjur), you provide:

FieldDescription
App NameA label for this connection inside DuoKey Cockpit.
Conjur Appliance URLhttps://conjur.internal.corp
AccountThe Conjur account (organization) name, e.g. myorg.
LoginThe identity Cockpit authenticates as, e.g. host/dke-cockpit.
API KeyThe API key for the configured login identity.
CA CertificateOptional PEM certificate for appliances using a self-signed or private CA.
Verify SSLWhether Cockpit validates the appliance TLS certificate. Enabled by default; only disable for trusted lab/test appliances.
Test before you save

Use the Test Connection action in the wizard to verify the account, login, and API key against your Conjur appliance before saving the connection.

Prerequisites​

Prerequisites

  • A reachable CyberArk Conjur appliance (Open Source, Enterprise, or Conjur Cloud)
  • A Conjur identity (e.g. a host identity such as host/dke-cockpit) with policy granting it access to the variables Cockpit should manage
  • The API key for that identity
  • Network connectivity (HTTPS) from DuoKey Cockpit to the Conjur appliance
  • DuoKey Cockpit account with permission to manage Secret Managers

Use Cases​

Centralized Secret Governance

Keep secrets under Conjur's existing policy model while giving DuoKey Cockpit administrators a single place to inspect and manage them.

Hybrid Secret Estates

Combine a Conjur connection with other supported secret manager backends (HashiCorp Vault, OpenBao, Azure Key Vault, AWS Secrets Manager, GCP Secret Manager) under one Cockpit view.

Self-Signed / On-Prem Appliances

Connect to on-premises Conjur appliances using a custom CA certificate, common for internal deployments.

Compliance & Audit

Track who added, tested, or used a Conjur connection through DuoKey Cockpit's audit trail.

Security Considerations​

  • Cockpit re-authenticates to Conjur for every operation rather than caching a long-lived session, limiting the exposure window of an access token.
  • TLS certificate validation is enabled by default; disabling it (or pinning a custom CA) should be reserved for appliances that cannot present a publicly trusted certificate.
  • The configured API key is stored encrypted by DuoKey Cockpit and is never displayed again after it is saved - rotate it in Conjur and update the Cockpit connection if it needs to change.
  • Access is bounded by whatever policy Conjur grants to the configured login identity - scope that identity to only the variables Cockpit needs.

Support​

For technical support or questions about the DuoKey CyberArk Conjur integration:

Important

Our integration specialists are available to help you plan a CyberArk Conjur secret manager connection for your organization. Contact us for assistance.