Prerequisites

Before you deploy Delinea Credentials Cache, make sure that the requirements in the Common section are met, then review the section for your deployment path. If you plan to use event-driven refresh, also review Event-Driven Refresh.

Common Requirements

Resource Requirements

The following minimum hardware configuration is recommended for the server or container host that runs Delinea Credentials Cache:

Resource Minimum Recommended
RAM 8 GB or more
CPU 2 or more cores
Disk Space 1 GB or more

Network Access

  • The host can reach the Delinea marketplace download server to download the package or container image.

  • The host can reach your Secret Server or Delinea Platform instance over HTTPS.

  • The client applications that will use the cache can reach the host over the HTTP or HTTPS port you expose.

Vault

One of the following vaults is installed, provisioned, and configured in your environment, and you have administrator permissions to log in to it:

  • Secret Server (Secret Server Cloud or Secret Server On-Premises), version 11.x or later. For more information about installing and configuring Secret Server, see the Secret Server documentation.

  • Delinea Platform (Secret Server on the Platform). For more information about provisioning and configuring the Delinea Platform, see the Delinea Platform documentation.

You also need an application account (Secret Server) or service user (Delinea Platform) whose credentials the cache uses to authenticate to the vault, with the View Secret permission on the secrets to be cached. The account requirements are described in the event-driven refresh configuration topics.

Windows (IIS)

  • A supported version of Windows Server. IIS is included with the operating system and is enabled during installation.

  • Administrator privileges on the Windows host.

  • The ASP.NET Core 10.0 Hosting Bundle. The Hosting Bundle installs the .NET 10.0 runtime and the IIS module required to host ASP.NET Core applications. Installation is covered in Installing Delinea Credentials Cache on Windows.

  • (HTTPS only) A certificate for the server's fully qualified domain name, either issued by a trusted certificate authority or self-signed for testing.

Linux (Apache HTTP Server)

  • Ubuntu Linux or Red Hat Enterprise Linux (RHEL).

  • Root or sudo privileges on the Linux host.

  • The ASP.NET Core 10.0 runtime (aspnetcore-runtime-10.0) from the Microsoft package repository. Installation is covered in Installing Delinea Credentials Cache on Linux.

  • Apache HTTP Server (apache2 on Ubuntu, httpd on RHEL) available for installation, with the proxy, proxy_http, and (for HTTPS) ssl modules.

  • (HTTPS only) OpenSSL to generate a self-signed certificate, or a certificate issued by a trusted certificate authority.

Docker

Component Purpose
Docker Runs the Delinea Credentials Cache container on Windows, Linux, or macOS
PowerShell, Command Prompt, or a Linux terminal Executes Docker commands
.NET SDK (dotnet CLI) on the host Only needed to generate the HTTPS development certificate with dotnet dev-certs; not required at run time
Secret Server or Delinea Platform instance Source vault from which the container retrieves and caches secrets

The container image includes the .NET runtime, so no runtime or reverse proxy needs to be installed on the host.

Event-Driven Refresh

Event-driven refresh is optional. If you want the cache to be refreshed immediately after a password change (see Event-Driven Secret Refresh), the following additional requirements apply.

Distributed Engine

You must have a Distributed Engine installed and configured in your environment. Event Pipelines execute on Distributed Engines, while Delinea Credentials Cache can be deployed on one or more servers reachable from those engines. To learn how to install and configure a Distributed Engine, see the Secret Server documentation.

Vault Permissions

The account you use to configure the integration must have permissions to:

  • Create and configure Event Pipeline policies (Administer Secret Server Pipelines).

  • Create PowerShell scripts (Administer Secret Server Scripts).

  • Associate Event Pipelines with secrets and read them (View Secret).

Enable Confidential Secret Fields in Event Pipelines

The Event Pipeline PowerShell script requires access to confidential secret fields (such as the password field) to authenticate with the Credentials Cache API. This access is controlled by a Secret Server configuration setting that is disabled by default.

If this setting is not enabled before you configure the Event Pipeline, the PowerShell script fails silently when it references password fields. Enable this setting before you proceed with the configuration topics.

To enable confidential secret field access in Event Pipelines:

  1. In Secret Server, navigate to Admin > Configuration > Advanced (or open https://<YOUR SECRET SERVER URL>/app/#/admin/advanced-config-settings directly).

  2. Locate the setting Event Pipelines: Allow Confidential Secret Fields to be used in Scripts.

  3. Set the value to True. The default value is False.

  4. Select Save.

This setting allows Event Pipeline script tasks to reference confidential fields such as $password. It must be set to True for event-driven refresh to work.

When all requirements are met, continue with Deployment Options.