# Manage secrets with a third-party credential manager

> Learn how to create a StormForge Agent secret and enable third-party credential management

---

LLMS index: [llms.txt](/llms.txt)

---

By default, StormForge uses Helm to create and update its credentials Secret. However, if you would like to use a third-party credential manager (for example, to rotate secrets), you can choose to disable Helm management of the credentials secret.

When Helm management of the credentials secret is disabled, you must:

- Create the `stormforge-system` namespace before you install the agent.
- Create the `stormforge-auth` secret, and populate it with the required credentials, before you install the agent.
- Maintain the `stormforge-auth` secret yourself, manually or with a third-party credential manager.

<div class="alert alert-info" role="alert"><div class="h4 alert-heading" role="heading">Note</div>


If you are **not** using a third-party credential management tool, you do **not** need to follow the steps in this guide. Instead, follow the steps in the [Install](/docs/installation/install/) topic. You still have to create an access credential (as described in the Install topic), but StormForge will create and manage the secret for you.
</div>


Before you begin, make sure that the StormForge CLI tool is [installed](/docs/installation/install-adv/#prepare-to-install).

## Steps

1. Log in to your StormForge account.

    ```sh
    stormforge login
    ```

1. Generate an access credential and save the output to a file.
    - Replace CREDENTIAL_NAME with a name that will help you identify the credential (such as the name of the cluster you're installing on).
    - Replace CREDENTIAL_FILE with a filename that will help you identify the file that contains the credential.

    ```sh
    stormforge auth create CREDENTIAL_NAME > CREDENTIAL_FILE
    ```

    The credential file will look something like this:

    ```yaml
    stormforge:
       address: https://api.stormforge.io/
    authorization:
       issuer: https://api.stormforge.io/
       clientID: CREDENTIAL_NAME 
       clientSecret: CREDENTIAL_SECRET
    ```

1. Create a StormForge Agent secret and save it to a file.  
    - Replace CLUSTER_NAME with the name of the cluster you're installing the Agent on.
    - Replace CREDENTIAL_FILE with the filename from the previous step.
    - Replace SECRET_FILE with a filename that will help you to identify the secret (for example, `stormforge-auth`).

        ```sh
        helm template stormforge oci://registry.stormforge.io/library/stormforge \
          -n stormforge-system \
          -s templates/auth-secret.yaml \
          -f CREDENTIAL_FILE \
          --set clusterName=CLUSTER_NAME \
        | grep -vi -e app.kubernetes.io/managed-by -e app.kubernetes.io/version -e helm.sh/chart \
        > SECRET_FILE
        ```

    The secret file will look something like this:

    ```yaml
    ---
    # Source: stormforge/templates/common/auth-secret.yaml
    apiVersion: v1
    kind: Secret
    type: Opaque
    metadata:
      name: "stormforge-auth"
      namespace: "stormforge-system"
      labels:
        app.kubernetes.io/name: stormforge
        app.kubernetes.io/instance: stormforge
    data:
      STORMFORGE_CLIENT_ID: "**********"
      STORMFORGE_CLIENT_SECRET: "**********"
      STORMFORGE_ISSUER: "**********"
      STORMFORGE_SERVER: "**********"
    ```

1. Create the `stormforge-system` namespace and then apply the secret.
    - Replace SECRET_FILE with the name of the file that contains the secret that you generated in the previous step.

    ```sh
    kubectl create namespace stormforge-system
    kubectl apply -f SECRET_FILE -n stormforge-system
    ```

1. When you're ready to install StormForge, include `--set createAuthSecret=false` to indicate to StormForge that you or a third-party credential management tool will manage the secret.

    - Replace CLUSTER_NAME with the name of the cluster (lowercase, no underscore) you're installing on.

    ```sh
    helm install stormforge oci://registry.stormforge.io/library/stormforge \
      --namespace stormforge-system \
      --set clusterName=CLUSTER_NAME \
      --set createAuthSecret=false
    ```

## Related topics

- [`stormforge auth`](/docs/stormforge-cli/reference/#stormforge-auth) command (CLI reference)
