The OpenBao Secrets service is fully integrated with the EWC IAM. Users can authenticate using their tenancy credentials through the OIDC provider. Follow the steps below to access the system.
1. Open the authentication page
Navigate to:
https://secrets-val.europeanweather.cloud/ui/vault/auth?with=oidc
This page displays the available authentication methods.
2. Select the OIDC authentication method
Choose OIDC from the list of authentication options. This method enables login through the EWC IAM.
3. Start the OIDC login flow
Click “Sign in with OIDC provider”. You will be redirected to a new window managed by the EWC IAM.
4. Enter your tenancy name
In the IAM login window:
Provide your tenancy name
Proceed with your EWC IAM credentials or Federated IAM (e.g. ECMWF SSO, EUMETSAT EOPortal)
Once authenticated, you will be returned to the OpenBao UI with a valid session token.
5. Access the Secrets UI
After successful login, you will arrive to the root namespace of your tenancy.
You don't have to do anything here as it is just for logging in, you have to switch to your namespace on the low left corner to start using the secret manager→ select your tenancy name.
5. You are ready to start using the EWC Secret Manager
At the point you will arrive to your tenancy namespace, where you have secret engines enabled. If you want to know more about them, check the following page: EWC Secret Manager - Mount/Secret Engine
NOTE: You will have access to all resources assigned to your tenancy, but depending on the roles you have you might have access to more or less resources/actions, please check EWC Secret Manager - User Roles and Permissions


