--- # generated by https://github.com/hashicorp/terraform-plugin-docs page_title: "dokploy_vault_provider Resource - dokploy" subcategory: "" description: |- An external secret manager Dokploy resolves environment variables from at deploy time. Reference a secret from any env value with ${{vault..}}. The value is fetched when the deployment runs and is never stored in Dokploy — so rotating it in the vault takes effect on the next deploy with no Terraform change. Supported providerType values: hashicorp (Vault/OpenBao), infisical, aws (Secrets Manager), doppler, azure (Key Vault) and scaleway. config = jsonencode({ providerType = "hashicorp" url = "https://vault.example.com" token = var.vault_token mount = "secret" }) ~> Dokploy masks the credentials when reading a provider back, so Terraform keeps the value you configured. Drift in config is not detected. --- # dokploy_vault_provider (Resource) An external secret manager Dokploy resolves environment variables from at deploy time. Reference a secret from any `env` value with `${{vault..}}`. The value is fetched when the deployment runs and is never stored in Dokploy — so rotating it in the vault takes effect on the next deploy with no Terraform change. Supported `providerType` values: `hashicorp` (Vault/OpenBao), `infisical`, `aws` (Secrets Manager), `doppler`, `azure` (Key Vault) and `scaleway`. ```hcl config = jsonencode({ providerType = "hashicorp" url = "https://vault.example.com" token = var.vault_token mount = "secret" }) ``` ~> Dokploy masks the credentials when reading a provider back, so Terraform keeps the value you configured. Drift in `config` is not detected. ## Schema ### Required - `assignments` (String) JSON array scoping which projects or environments may resolve secrets from this provider. Pass `jsonencode([])` to leave it unscoped. - `config` (String, Sensitive) Provider credentials as a JSON object, including the `providerType` discriminator. - `name` (String) Name of the connection, unique within the organization. ### Read-Only - `created_at` (String) RFC 3339 timestamp of when the connection was created. - `id` (String) Unique vault provider identifier. - `organization_id` (String) Organization that owns the connection. - `provider_type` (String) Provider kind derived from `config`.