Back to modules
Secrets Module logo

Secrets Module

External secrets management for Ignition 8.3

Keep credentials out of your gateway: referenced secrets resolve straight from HashiCorp Vault, Azure Key Vault, AWS Secrets Manager or Google Secret Manager — cached, rotated without restarts, and fully audited.

Free in Ignition trial mode · €600 per gateway, perpetual · Basic Care updates 20% per year

What this module gives you

Credentials leave the gateway

Database passwords, OPC and email credentials and script secrets resolve from your secrets manager at the moment of use. Nothing to copy between environments, nothing left behind in a gateway backup.

Rotation without restarts

Rotate a secret in the vault and the gateway picks it up windowlessly: no restart, no faulted connections, no maintenance window. Rotation detection tells you when it happened.

Works with the vault you already have

HashiCorp Vault (KV v2 and database engine), Azure Key Vault, AWS Secrets Manager and Google Secret Manager, each with platform-native auth options like AppRole, managed identity and instance roles.

Keeps serving when the vault is down

Caching with last-known-good fallback means a secrets-manager outage never takes the plant down, and every cached serve is audited so nothing happens silently.

Estate-ready, fully audited

Hub-and-spoke deployments over the Gateway Network are verified end to end, and every read lands in the gateway audit trail — including which edge gateway read which secret.

Made by Ignition integrators

Built by the Mustry team out of real plant-floor security work, and supported by the people who run it in production.

Security posture at a glance

4
external secrets managers
0
third-party jars bundled
0
inbound ports opened
72 h
grace period on a licence lapse

HashiCorp Vault (KV v2 and database engine), Azure Key Vault, AWS Secrets Manager and Google Secret Manager — plus a Cached Provider that wraps any of them for hub-and-spoke estates. Windowless rotation and the audit trail apply to every provider type.

What it looks like on the gateway

No separate UI to learn: the module registers its provider types on Ignition's native Secret Providers page. Both shots come from the module's own demo gateway.

Ignition gateway Secret Providers page listing Vault, Azure Key Vault, AWS Secrets Manager and Google Secret Manager providers from the module
Platform → Security → Secret Providers with the module installed: Vault, Azure, AWS and Google providers running side by side.
Ignition Create Secret Provider dialog showing the module's provider types next to the platform built-ins
Creating a provider: the module's types sit in the platform's own dialog, next to the built-in ones — including the Cached Provider for estates.

Why this module exists

Every Ignition gateway holds credentials: database passwords, OPC and email accounts, API keys used in scripts. Encrypted or not, they live inside the gateway, get copied between environments, and quietly outlive every rotation policy. Meanwhile IT already runs a secrets manager built for exactly this problem. This module connects the two worlds: secrets stay in Vault, Azure, AWS or Google Cloud under the rotation and access policies IT enforces, and Ignition resolves them at the moment of use — with caching so the plant floor never depends on a cloud round-trip. If NIS2 or IEC 62443 is on your roadmap, centralised credential management, enforced rotation and a complete audit trail are among the first controls an auditor asks about — and the hardest to retrofit.

Secure by construction

The module is outbound-only: no listening sockets, no inbound firewall rules, and Gateway Network links in an estate are outbound-initiated from the edge. It bundles zero third-party jars, so there is no vendored dependency tree to patch. Every secret read lands in the gateway audit trail, and if a licence ever lapses there is a 72-hour grace period in which cached values keep serving with explicit warnings before reads fail — your process never stops unannounced.

What you get

An Ignition module, a user manual covering install through provider setup, rotation and hub-and-spoke estate deployment, and a configuration walkthrough for your gateway. Requires Ignition 8.3.3 or later on a standard gateway, gateway scope only — Ignition Edge loads modules from a fixed vendor list, so talk to us first if your architecture includes Edge gateways. Updates are available through our Basic Care module at 20% of the module price per year.

Request Secrets Module

Fill in the form and we will be in touch with purchase information.

Are you a system integrator?

System integrators get 20% off.

Order 10 or more modules for one end-customer in a single order and we apply a 50% discount.