Configuring Delinea Credentials Cache
Delinea Credentials Cache settings control how long secrets stay cached, how the service logs, and which vaults it accepts. On Windows and Linux, the settings live in the CredSettings section of the appsettings.json file in the installation directory. In a Docker container, the same settings are supplied as environment variables on the docker run command, using the CredSettings__ prefix (two underscores) in place of the section name.
Configuration Location
-
Windows (IIS):
C:\inetpub\wwwroot\DelineaCredentialCache_Windows\appsettings.json(or the physical path you chose for the IIS application). -
Linux:
~/credcache/appsettings.json(or the directory you extracted the package into; the same directory asWorkingDirectoryincredcache.service). -
Docker: no file to edit. Pass each setting with an
-eflag ondocker run, as shown in Deploying Delinea Credentials Cache as a Docker Container.
Settings
Setting (key under CredSettings in appsettings.json) |
Environment variable (Docker) | Default | Description |
|---|---|---|---|
CredCacheExpirationInMinutes
|
CredSettings__CredCacheExpirationInMinutes
|
10
|
Time-to-live (TTL) in minutes. Determines how long a cached secret remains valid before it expires and is automatically removed from the cache. After expiry, the next request for the secret fetches the current value from the vault. If a secret is rotated within the TTL window, the cache returning the previous value is expected behavior unless event-driven refresh is configured. |
EnableLogging
|
CredSettings__EnableLogging
|
false
|
Set to true to enable file-based logging. Logging is required to verify cache activity because there is no direct way to inspect cached secrets. |
LogPath
|
CredSettings__LogPath
|
Empty | Directory where the service writes log files, for example C:\DCC\Logs or /var/log/credcache. On Docker, mount a host directory to this path with -v so the logs survive container restarts. |
LogFrequency
|
CredSettings__LogFrequency
|
Hourly
|
How often the service starts a new log file. |
LogRetentionCount
|
CredSettings__LogRetentionCount
|
5
|
Maximum number of log files kept. When a new file is created, the oldest one is deleted. |
LogFileSizeLimitMB
|
CredSettings__LogFileSizeLimitMB
|
50
|
Maximum size of a single log file, in megabytes. |
SkipSSLVerification
|
CredSettings__SkipSSLVerification
|
false
|
Set to true to skip TLS certificate validation when the service connects to the vault. Use only in test environments, or as a temporary workaround while a trusted certificate is installed. In production, leave this set to false and make sure the host trusts the vault certificate. |
RequireHttpsVault
|
CredSettings__RequireHttpsVault
|
false
|
Set to true to reject vault URLs that use plain http://. Recommended hardening for production deployments. |
AllowedVaultUrls
|
CredSettings__AllowedVaultUrls
|
Empty (any vault URL accepted) | List of vault URLs that the /api/token endpoint accepts, matched by scheme, host and port. The vault URL is supplied by the client in each token request; leaving this list empty means any well-formed URL is accepted. Populate it with your Secret Server or Delinea Platform URL to restrict the service to known vaults. In Docker, pass list items as indexed variables, for example -e CredSettings__AllowedVaultUrls__0=https://vault.example.com. |
Example appsettings.json
The file as shipped, with logging enabled and a log path added. Lines that begin with // are comments included by Delinea and can be left in place.
{
"Logging": {
"LogLevel": {
"Default": "Information",
"Microsoft.AspNetCore": "Warning"
}
},
"CredSettings": {
"CredCacheExpirationInMinutes": 10,
"LogFrequency": "Hourly",
"LogPath": "C:\\DCC\\Logs",
"EnableLogging": true,
"SkipSSLVerification": false,
"RequireHttpsVault": false,
"AllowedVaultUrls": [],
"LogRetentionCount": 5,
"LogFileSizeLimitMB": 50
},
"DataProtection": {
"KeyPath": "Keys"
},
"AllowedHosts": "*"
}
Do not remove the Logging, DataProtection, or AllowedHosts sections. They are used by the service and are not intended to be changed.
On Linux, use a Linux path for LogPath, for example "/var/log/credcache", and make sure that the account in the User= line of credcache.service can write to it.
Changing a Setting
Windows and Linux
-
Open the
appsettings.jsonfile in a text editor. -
Locate the setting inside the
CredSettingssection, for exampleCredCacheExpirationInMinutes. -
Set the value. For the TTL, enter the desired expiration time in minutes, for example
15for 15 minutes or20for 20 minutes. -
Save the file.
-
Restart the service for the change to take effect (see below).
Docker
Environment variables are fixed when a container is created. Stop and remove the container, then run docker run again with the new -e value:
docker stop delinea-credential-cache
docker rm delinea-credential-cache
docker run -d --name delinea-credential-cache ... -e CredSettings__CredCacheExpirationInMinutes=15 ... delinea-credential-cache:<version>
Restarting the Service
-
Windows (IIS): In IIS Manager, select Application Pools, select the pool used by the Credentials Cache application, and select Recycle in the Actions pane. Alternatively, run
iisresetfrom an administrator command prompt (this restarts all sites on the server). -
Linux:
sudo systemctl restart credcache.service -
Docker:
docker restart delinea-credential-cache(for a change that does not involve environment variables), or recreate the container as described above.
Restarting the service clears the in-memory cache. The first request for each secret after a restart is served from the vault.
Choosing a TTL
A shorter TTL reduces the window in which a rotated secret can be served from the cache, at the cost of more calls to the vault. A longer TTL reduces vault load but increases that window. If your secrets are rotated automatically and applications must never receive a stale value, keep the TTL at its default and configure Event-Driven Secret Refresh, which updates the cache immediately after each password change regardless of the TTL.