OpenStack Barbican
E699767
OpenStack Barbican is a key management and secrets storage service designed for securely managing encryption keys, passwords, and other sensitive data within OpenStack cloud environments.
Statements (48)
| Predicate | Object |
|---|---|
| instanceOf |
Key management service
ⓘ
Open source software project ⓘ Secrets management service ⓘ |
| belongsToDomain |
Cloud computing
ⓘ
Cloud security ⓘ Key management systems ⓘ |
| configuration |
Can use hardware-based key managers
ⓘ
Can use software-based key managers ⓘ |
| designedFor | OpenStack cloud environments NERFINISHED ⓘ |
| developedBy | OpenStack community NERFINISHED ⓘ |
| hasPurpose |
Manage passwords and credentials
ⓘ
Provide key management for OpenStack services ⓘ Securely manage encryption keys ⓘ Securely store secrets ⓘ |
| integratesWith |
OpenStack Cinder
NERFINISHED
ⓘ
OpenStack Glance NERFINISHED ⓘ OpenStack Keystone NERFINISHED ⓘ OpenStack Nova NERFINISHED ⓘ OpenStack Octavia NERFINISHED ⓘ |
| license | Apache License 2.0 ⓘ |
| partOf | OpenStack NERFINISHED ⓘ |
| programmingLanguage | Python ⓘ |
| providesInterface | REST API ⓘ |
| releaseModel | Time-based OpenStack release cycle ⓘ |
| repository | https://opendev.org/openstack/barbican ⓘ |
| securityProperty |
Encrypts secrets at rest
ⓘ
Transmits secrets over TLS ⓘ |
| supportsConcept |
Orders for asynchronous operations
ⓘ
Projects as tenants ⓘ Secret containers ⓘ |
| supportsFeature |
Access control via Keystone
ⓘ
Auditability of secret operations ⓘ Hardware Security Module integration ⓘ Multi-tenant secret isolation ⓘ Pluggable crypto backends ⓘ |
| supportsFunction |
Certificate management
ⓘ
Key generation ⓘ Key retrieval ⓘ Key rotation ⓘ Key storage ⓘ Secret retrieval ⓘ Secret storage ⓘ Secure API access to secrets ⓘ |
| usedFor |
Storing API keys
ⓘ
Storing TLS certificates ⓘ Storing database passwords ⓘ Storing encryption keys for volumes ⓘ |
| website | https://docs.openstack.org/barbican/latest/ ⓘ |
Referenced by (1)
Full triples — surface form annotated when it differs from this entity's canonical label.