Deploying Delinea Credentials Cache as a Docker Container

Delinea Credentials Cache (DCC) is available as a Docker container image. Running the cache in a container provides a portable, repeatable deployment and does not require installing a .NET runtime or configuring a reverse proxy on the host operating system.

This topic covers downloading and loading the container image, configuring certificates for HTTPS and Secret Server trust, running the container, and basic container management.

Before you begin, make sure that the requirements in Prerequisites are met.

Step 1: Download the Container Image

  1. Obtain the Delinea Credentials Cache container image (a zip archive) from Delinea Support.

  2. Extract the contents of the archive. The archive contains the container image as a .tar file, for example delinea-credential-cache-2.2.0.tar.

  3. Note the path to the extracted .tar file and the version number in its filename. The commands in the following sections require both.

Step 2: Prepare the Certificates

The container uses two certificates:

Certificate Purpose
ASP.NET Core HTTPS certificate (aspnetapp.pfx) Kestrel uses this certificate inside the container to serve the API over HTTPS (port 8443)
Secret Server certificate (SecretServerCertificate.crt) Establishes trust with the Secret Server HTTPS endpoint when the container communicates with Secret Server APIs

If the Secret Server endpoint uses a certificate from a public certificate authority that the container's base OS image already trusts, skip the Secret Server certificate steps below.

Creating the ASP.NET Core HTTPS Certificate

Kestrel requires this certificate to enable HTTPS inside the container.

  1. Create a certificate directory on the host machine.

    Windows:

    mkdir C:\DCC\Certificates
    cd C:\DCC\Certificates

    Linux / macOS:

    mkdir -p ~/dcc/certificates
    cd ~/dcc/certificates

  2. Generate the HTTPS certificate. Replace <your-certificate-password> with a strong password.

    Windows:

    dotnet dev-certs https -ep C:\DCC\Certificates\aspnetapp.pfx -p <your-certificate-password>

    Linux / macOS:

    dotnet dev-certs https -ep ~/dcc/certificates/aspnetapp.pfx -p <your-certificate-password>

    This creates the file aspnetapp.pfx in the certificate directory.

    Record this password. The docker run command requires it during container configuration.

  3. (Optional) Trust the certificate for local testing:

    dotnet dev-certs https --trust

    This allows a browser on the host machine to trust the certificate. This step applies only to local development or testing scenarios. For production, use a certificate issued by a trusted certificate authority and export it as a password-protected .pfx file.

  4. Verify that the certificate file exists.

    Windows:

    dir C:\DCC\Certificates

    Linux / macOS:

    ls ~/dcc/certificates

    Confirm that aspnetapp.pfx appears in the output.

Exporting the Secret Server Certificate

The container requires this certificate to trust the Secret Server HTTPS endpoint. This procedure applies when Secret Server uses an internal or self-signed certificate.

  1. Open the Secret Server URL in Chrome: https://<your-secret-server-url>

  2. Select the lock icon in the address bar.

  3. Select Connection is secure.

  4. Select Certificate is valid.

  5. On the Details tab, select Copy to File.

  6. Select the export format Base-64 encoded X.509 (.CER).

  7. Save the file as SecretServerCertificate.crt in the same certificate directory created earlier.

  8. Verify that both certificate files exist in the directory.

    Windows:

    dir C:\DCC\Certificates

    Linux / macOS:

    ls ~/dcc/certificates

    Expected files: aspnetapp.pfx and SecretServerCertificate.crt.

Step 3: Load the Container Image

  1. Load the image into Docker:

    docker load -i <path-to-tar-file>/delinea-credential-cache-<version>.tar

  2. Verify that the image appears in Docker:

    docker images

    The output includes a row for delinea-credential-cache with the tag matching the deployed version.

Step 4: Run the Container

The following command starts Delinea Credentials Cache with both HTTP and HTTPS enabled, logging turned on, and the Secret Server trust certificate mounted.

Replace <your-certificate-password> with the password set during HTTPS certificate generation, <version> with the image version, and update the volume mount paths to match the certificate directory on the host machine.

Windows (PowerShell):

docker run -d `
  --name delinea-credential-cache `
  -p 8083:8080 `
  -p 8443:8443 `
  -e ASPNETCORE_URLS="http://+:8080;https://+:8443" `
  -e ASPNETCORE_Kestrel__Certificates__Default__Password=<your-certificate-password> `
  -e ASPNETCORE_Kestrel__Certificates__Default__Path=/https/aspnetapp.pfx `
  -e CredSettings__CredCacheExpirationInMinutes=5 `
  -e CredSettings__EnableLogging=true `
  -e CredSettings__LogPath=/app/logs `
  -v C:\DCC\Certificates:/https `
  -v C:\DCC\logs:/app/logs `
  -v C:\DCC\Certificates\SecretServerCertificate.crt:/usr/local/share/ca-certificates/customer-root.crt `
  delinea-credential-cache:<version>

Linux / macOS:

docker run -d \
  --name delinea-credential-cache \
  -p 8083:8080 \
  -p 8443:8443 \
  -e ASPNETCORE_URLS="http://+:8080;https://+:8443" \
  -e ASPNETCORE_Kestrel__Certificates__Default__Password=<your-certificate-password> \
  -e ASPNETCORE_Kestrel__Certificates__Default__Path=/https/aspnetapp.pfx \
  -e CredSettings__CredCacheExpirationInMinutes=5 \
  -e CredSettings__EnableLogging=true \
  -e CredSettings__LogPath=/app/logs \
  -v ~/dcc/certificates:/https \
  -v ~/dcc/logs:/app/logs \
  -v ~/dcc/certificates/SecretServerCertificate.crt:/usr/local/share/ca-certificates/customer-root.crt \
  delinea-credential-cache:<version>

After the container starts, the Swagger UI is available at:

  • HTTP: http://<hostname>:8083/swagger

  • HTTPS: https://<hostname>:8443/swagger

If Secret Server uses a certificate from a publicly trusted CA and backend certificate trust is not required, remove the following volume mount from the command:

-v <certificate-path>/SecretServerCertificate.crt:/usr/local/share/ca-certificates/customer-root.crt

Mounting a .crt file into /usr/local/share/ca-certificates/ does not by itself make the container trust the certificate. On Debian- and Ubuntu-based container images, the update-ca-certificates command must also run for the certificate to take effect. If the container image does not run this command at startup, run it manually after each start:

docker exec delinea-credential-cache update-ca-certificates

For the settings that you can pass with -e, see Configuring Delinea Credentials Cache. For the API endpoints available after startup, see API Reference.

Container Management

Check Container Status

docker ps -a --filter "name=delinea-credential-cache"

View Container Logs

docker logs delinea-credential-cache

To stream logs in real time:

docker logs -f delinea-credential-cache

Access the Container Shell

For advanced troubleshooting, open an interactive shell:

docker exec -it delinea-credential-cache /bin/bash

Restart the Container

docker restart delinea-credential-cache

Environment variables are fixed when a container is created. To change a -e value, stop and remove the container and run docker run again with the new value.

Stop and Remove a Container

docker stop delinea-credential-cache
docker rm delinea-credential-cache

Remove the Image

docker rmi delinea-credential-cache:<version>

Running Multiple Instances

To run more than one instance on the same host, assign a unique container name and a unique host port to each instance:

docker run -d --name dcc-1 -p 8081:8080 -e ASPNETCORE_URLS=http://+:8080 delinea-credential-cache:<version>

docker run -d --name dcc-2 -p 8082:8080 -e ASPNETCORE_URLS=http://+:8080 delinea-credential-cache:<version>

Each instance requires a unique container name (--name) and host port (-p). The container-internal port stays the same across instances. For guidance on when to run several instances, see Architecture.

Next Steps