Configuring Delinea Credentials Cache

Delinea Credentials Cache settings control how long secrets stay cached, how the service logs, and which vaults it accepts. On Windows and Linux, the settings live in the CredSettings section of the appsettings.json file in the installation directory. In a Docker container, the same settings are supplied as environment variables on the docker run command, using the CredSettings__ prefix (two underscores) in place of the section name.

Configuration Location

  • Windows (IIS): C:\inetpub\wwwroot\DelineaCredentialCache_Windows\appsettings.json (or the physical path you chose for the IIS application).

  • Linux: ~/credcache/appsettings.json (or the directory you extracted the package into; the same directory as WorkingDirectory in credcache.service).

  • Docker: no file to edit. Pass each setting with an -e flag on docker run, as shown in Deploying Delinea Credentials Cache as a Docker Container.

Settings

Setting (key under CredSettings in appsettings.json) Environment variable (Docker) Default Description
CredCacheExpirationInMinutes CredSettings__CredCacheExpirationInMinutes 10 Time-to-live (TTL) in minutes. Determines how long a cached secret remains valid before it expires and is automatically removed from the cache. After expiry, the next request for the secret fetches the current value from the vault. If a secret is rotated within the TTL window, the cache returning the previous value is expected behavior unless event-driven refresh is configured.
EnableLogging CredSettings__EnableLogging false Set to true to enable file-based logging. Logging is required to verify cache activity because there is no direct way to inspect cached secrets.
LogPath CredSettings__LogPath Empty Directory where the service writes log files, for example C:\DCC\Logs or /var/log/credcache. On Docker, mount a host directory to this path with -v so the logs survive container restarts.
LogFrequency CredSettings__LogFrequency Hourly How often the service starts a new log file.
LogRetentionCount CredSettings__LogRetentionCount 5 Maximum number of log files kept. When a new file is created, the oldest one is deleted.
LogFileSizeLimitMB CredSettings__LogFileSizeLimitMB 50 Maximum size of a single log file, in megabytes.
SkipSSLVerification CredSettings__SkipSSLVerification false Set to true to skip TLS certificate validation when the service connects to the vault. Use only in test environments, or as a temporary workaround while a trusted certificate is installed. In production, leave this set to false and make sure the host trusts the vault certificate.
RequireHttpsVault CredSettings__RequireHttpsVault false Set to true to reject vault URLs that use plain http://. Recommended hardening for production deployments.
AllowedVaultUrls CredSettings__AllowedVaultUrls Empty (any vault URL accepted) List of vault URLs that the /api/token endpoint accepts, matched by scheme, host and port. The vault URL is supplied by the client in each token request; leaving this list empty means any well-formed URL is accepted. Populate it with your Secret Server or Delinea Platform URL to restrict the service to known vaults. In Docker, pass list items as indexed variables, for example -e CredSettings__AllowedVaultUrls__0=https://vault.example.com.

Example appsettings.json

The file as shipped, with logging enabled and a log path added. Lines that begin with // are comments included by Delinea and can be left in place.

{
  "Logging": {
    "LogLevel": {
      "Default": "Information",
      "Microsoft.AspNetCore": "Warning"
    }
  },
  "CredSettings": {
    "CredCacheExpirationInMinutes": 10,
    "LogFrequency": "Hourly",
    "LogPath": "C:\\DCC\\Logs",
    "EnableLogging": true,
    "SkipSSLVerification": false,
    "RequireHttpsVault": false,
    "AllowedVaultUrls": [],
    "LogRetentionCount": 5,
    "LogFileSizeLimitMB": 50
  },
  "DataProtection": {
    "KeyPath": "Keys"
  },
  "AllowedHosts": "*"
}

Do not remove the Logging, DataProtection, or AllowedHosts sections. They are used by the service and are not intended to be changed.

On Linux, use a Linux path for LogPath, for example "/var/log/credcache", and make sure that the account in the User= line of credcache.service can write to it.

Changing a Setting

Windows and Linux

  1. Open the appsettings.json file in a text editor.

  2. Locate the setting inside the CredSettings section, for example CredCacheExpirationInMinutes.

  3. Set the value. For the TTL, enter the desired expiration time in minutes, for example 15 for 15 minutes or 20 for 20 minutes.

  4. Save the file.

  5. Restart the service for the change to take effect (see below).

Docker

Environment variables are fixed when a container is created. Stop and remove the container, then run docker run again with the new -e value:

docker stop delinea-credential-cache
docker rm delinea-credential-cache
docker run -d --name delinea-credential-cache ... -e CredSettings__CredCacheExpirationInMinutes=15 ... delinea-credential-cache:<version>

Restarting the Service

  • Windows (IIS): In IIS Manager, select Application Pools, select the pool used by the Credentials Cache application, and select Recycle in the Actions pane. Alternatively, run iisreset from an administrator command prompt (this restarts all sites on the server).

  • Linux: sudo systemctl restart credcache.service

  • Docker: docker restart delinea-credential-cache (for a change that does not involve environment variables), or recreate the container as described above.

Restarting the service clears the in-memory cache. The first request for each secret after a restart is served from the vault.

Choosing a TTL

A shorter TTL reduces the window in which a rotated secret can be served from the cache, at the cost of more calls to the vault. A longer TTL reduces vault load but increases that window. If your secrets are rotated automatically and applications must never receive a stale value, keep the TTL at its default and configure Event-Driven Secret Refresh, which updates the cache immediately after each password change regardless of the TTL.