Delinea Credentials Cache
Delinea Credentials Cache is a web service that caches secrets from Secret Server or the Delinea Platform and provides those secrets to client applications. The service reduces the number of repeated API calls to the vault for the same secret, which improves the performance of the applications that depend on it. Delinea Credentials Cache can be deployed on Windows, on Linux, or as a Docker container, and is accessed over HTTP or HTTPS.
Delinea Credentials Cache supports all Secret Server secret templates. The cache captures and stores every type of secret, including credentials, SSH private and public keys, certificates, PEM files, and tokens.
Supported Vaults
Delinea Credentials Cache works with the following vaults:
-
Secret Server Cloud
-
Secret Server On-Premises
-
Secret Server on the Delinea Platform
Supported Secret Types
Because the cache stores any secret that is requested through its API, it is not limited to a specific template or integration. Supported secret types include:
-
Username and password credentials
-
SSH private and public keys
-
Certificates and PEM files
-
Tokens
In This Section
-
Use Cases and Supported Integrations — why to deploy Delinea Credentials Cache and which integrations have been tested with it.
-
Architecture — how the service, the vault, the Distributed Engine, and Event Pipelines fit together, including multi-instance and high-availability behavior.
-
Deployment Options — a comparison of the Windows, Linux, and Docker deployment paths.
-
Prerequisites — hardware, runtime, vault, and permission requirements for every deployment path.
-
Installing Delinea Credentials Cache on Windows — IIS-hosted installation.
-
Installing Delinea Credentials Cache on Linux — systemd service behind an Apache HTTP Server reverse proxy on Ubuntu or RHEL.
-
Deploying Delinea Credentials Cache as a Docker Container — container image, certificates, and
docker run. -
Configuring Delinea Credentials Cache — cache expiration, logging, and the other
appsettings.jsonand environment-variable settings. -
Event-Driven Secret Refresh — refreshing the cache immediately after a password change by using Event Pipelines.
-
Verifying the Deployment — checks per hosting platform, per integration, and for event-driven refresh.
-
API Reference — Swagger UI access and the token, credential, and secret-changed endpoints.
-
Troubleshooting — symptoms, causes, and where to find logs.