The OpenBao Secrets service is fully integrated with the EWC IAM. Users can authenticate using their tenancy credentials through the OIDC provider. Follow the steps below to access the system.
1. Open the authentication page
Navigate to:
https://secrets-val.europeanweather.cloud/ui/vault/auth?with=oidc
This page displays the available authentication methods.
2. Select the OIDC authentication method
Choose OIDC from the list of authentication options. This method enables login through the EWC IAM.
3. Start the OIDC login flow
Click “Sign in with OIDC provider”. You will be redirected to a new window managed by the EWC IAM.
4. Enter your tenancy name
In the IAM login window:
Provide your tenancy name
Proceed with your EWC IAM credentials or Federated IAM (e.g. ECMWF SSO, EUMETSAT EOPortal)
Once authenticated, you will be returned to the OpenBao UI with a valid session token.
5. Access the Secrets UI
After successful login, you will arrive to the root namespace of your tenancy.
you don't have to do anything here, you have to switch to your namespace on the low left corner → select your tenancy name.
At the point you will arrive to your tenancy namespace, where you have secret engines enabled: EWC Secret Manager - Mount/Secret Engine
You will have access to all resources assigned to your tenancy. (depending on the roles you have you might have access to more or less resources, please check EWC Secret Manager - User Roles and Permissions )

