Deploying Delinea Credentials Cache as a Docker Container
Delinea Credentials Cache (DCC) is available as a Docker container image. Running the cache in a container provides a portable, repeatable deployment and does not require installing a .NET runtime or configuring a reverse proxy on the host operating system.
This topic covers downloading and loading the container image, configuring certificates for HTTPS and Secret Server trust, running the container, and basic container management.
Before you begin, make sure that the requirements in Prerequisites are met.
Step 1: Download the Container Image
-
Obtain the Delinea Credentials Cache container image (a zip archive) from Delinea Support.
-
Extract the contents of the archive. The archive contains the container image as a
.tarfile, for exampledelinea-credential-cache-2.2.0.tar. -
Note the path to the extracted
.tarfile and the version number in its filename. The commands in the following sections require both.
Step 2: Prepare the Certificates
The container uses two certificates:
| Certificate | Purpose |
|---|---|
ASP.NET Core HTTPS certificate (aspnetapp.pfx) |
Kestrel uses this certificate inside the container to serve the API over HTTPS (port 8443) |
Secret Server certificate (SecretServerCertificate.crt) |
Establishes trust with the Secret Server HTTPS endpoint when the container communicates with Secret Server APIs |
If the Secret Server endpoint uses a certificate from a public certificate authority that the container's base OS image already trusts, skip the Secret Server certificate steps below.
Creating the ASP.NET Core HTTPS Certificate
Kestrel requires this certificate to enable HTTPS inside the container.
-
Create a certificate directory on the host machine.
Windows:
mkdir C:\DCC\Certificatescd C:\DCC\CertificatesLinux / macOS:
mkdir -p ~/dcc/certificatescd ~/dcc/certificates -
Generate the HTTPS certificate. Replace
<your-certificate-password>with a strong password.Windows:
dotnet dev-certs https -ep C:\DCC\Certificates\aspnetapp.pfx -p <your-certificate-password>Linux / macOS:
dotnet dev-certs https -ep ~/dcc/certificates/aspnetapp.pfx -p <your-certificate-password>This creates the file
aspnetapp.pfxin the certificate directory.Record this password. The
docker runcommand requires it during container configuration. -
(Optional) Trust the certificate for local testing:
dotnet dev-certs https --trustThis allows a browser on the host machine to trust the certificate. This step applies only to local development or testing scenarios. For production, use a certificate issued by a trusted certificate authority and export it as a password-protected
.pfxfile. -
Verify that the certificate file exists.
Windows:
dir C:\DCC\CertificatesLinux / macOS:
ls ~/dcc/certificatesConfirm that
aspnetapp.pfxappears in the output.
Exporting the Secret Server Certificate
The container requires this certificate to trust the Secret Server HTTPS endpoint. This procedure applies when Secret Server uses an internal or self-signed certificate.
-
Open the Secret Server URL in Chrome:
https://<your-secret-server-url> -
Select the lock icon in the address bar.
-
Select Connection is secure.
-
Select Certificate is valid.
-
On the Details tab, select Copy to File.
-
Select the export format Base-64 encoded X.509 (.CER).
-
Save the file as
SecretServerCertificate.crtin the same certificate directory created earlier. -
Verify that both certificate files exist in the directory.
Windows:
dir C:\DCC\CertificatesLinux / macOS:
ls ~/dcc/certificatesExpected files:
aspnetapp.pfxandSecretServerCertificate.crt.
Step 3: Load the Container Image
-
Load the image into Docker:
docker load -i <path-to-tar-file>/delinea-credential-cache-<version>.tar -
Verify that the image appears in Docker:
docker imagesThe output includes a row for
delinea-credential-cachewith the tag matching the deployed version.
Step 4: Run the Container
The following command starts Delinea Credentials Cache with both HTTP and HTTPS enabled, logging turned on, and the Secret Server trust certificate mounted.
Replace <your-certificate-password> with the password set during HTTPS certificate generation, <version> with the image version, and update the volume mount paths to match the certificate directory on the host machine.
Windows (PowerShell):
docker run -d `
--name delinea-credential-cache `
-p 8083:8080 `
-p 8443:8443 `
-e ASPNETCORE_URLS="http://+:8080;https://+:8443" `
-e ASPNETCORE_Kestrel__Certificates__Default__Password=<your-certificate-password> `
-e ASPNETCORE_Kestrel__Certificates__Default__Path=/https/aspnetapp.pfx `
-e CredSettings__CredCacheExpirationInMinutes=5 `
-e CredSettings__EnableLogging=true `
-e CredSettings__LogPath=/app/logs `
-v C:\DCC\Certificates:/https `
-v C:\DCC\logs:/app/logs `
-v C:\DCC\Certificates\SecretServerCertificate.crt:/usr/local/share/ca-certificates/customer-root.crt `
delinea-credential-cache:<version>
Linux / macOS:
docker run -d \
--name delinea-credential-cache \
-p 8083:8080 \
-p 8443:8443 \
-e ASPNETCORE_URLS="http://+:8080;https://+:8443" \
-e ASPNETCORE_Kestrel__Certificates__Default__Password=<your-certificate-password> \
-e ASPNETCORE_Kestrel__Certificates__Default__Path=/https/aspnetapp.pfx \
-e CredSettings__CredCacheExpirationInMinutes=5 \
-e CredSettings__EnableLogging=true \
-e CredSettings__LogPath=/app/logs \
-v ~/dcc/certificates:/https \
-v ~/dcc/logs:/app/logs \
-v ~/dcc/certificates/SecretServerCertificate.crt:/usr/local/share/ca-certificates/customer-root.crt \
delinea-credential-cache:<version>
After the container starts, the Swagger UI is available at:
-
HTTP:
http://<hostname>:8083/swagger -
HTTPS:
https://<hostname>:8443/swagger
If Secret Server uses a certificate from a publicly trusted CA and backend certificate trust is not required, remove the following volume mount from the command:-v <certificate-path>/SecretServerCertificate.crt:/usr/local/share/ca-certificates/customer-root.crt
Mounting a .crt file into /usr/local/share/ca-certificates/ does not by itself make the container trust the certificate. On Debian- and Ubuntu-based container images, the update-ca-certificates command must also run for the certificate to take effect. If the container image does not run this command at startup, run it manually after each start:docker exec delinea-credential-cache update-ca-certificates
For the settings that you can pass with -e, see Configuring Delinea Credentials Cache. For the API endpoints available after startup, see API Reference.
Container Management
Check Container Status
docker ps -a --filter "name=delinea-credential-cache"
View Container Logs
docker logs delinea-credential-cache
To stream logs in real time:
docker logs -f delinea-credential-cache
Access the Container Shell
For advanced troubleshooting, open an interactive shell:
docker exec -it delinea-credential-cache /bin/bash
Restart the Container
docker restart delinea-credential-cache
Environment variables are fixed when a container is created. To change a -e value, stop and remove the container and run docker run again with the new value.
Stop and Remove a Container
docker stop delinea-credential-cache
docker rm delinea-credential-cache
Remove the Image
docker rmi delinea-credential-cache:<version>
Running Multiple Instances
To run more than one instance on the same host, assign a unique container name and a unique host port to each instance:
docker run -d --name dcc-1 -p 8081:8080 -e ASPNETCORE_URLS=http://+:8080 delinea-credential-cache:<version>
docker run -d --name dcc-2 -p 8082:8080 -e ASPNETCORE_URLS=http://+:8080 delinea-credential-cache:<version>
Each instance requires a unique container name (--name) and host port (-p). The container-internal port stays the same across instances. For guidance on when to run several instances, see Architecture.
Next Steps
-
Confirm that the container is running and the Swagger UI loads: Verifying the Deployment.
-
If the container does not start or HTTPS does not work, see Troubleshooting.