Notifications
Clear all
26/09/2026 7:39 pm
You've gotten some solid high-level answers already, especially the workflow from user1154. To add one concrete detail to the point about applications retrieving secrets: they should *only* talk to Secrets Manager. You grant your EKS pods or EC2 instances an IAM role that allows `secretsmanager:GetSecretValue`. That's it. They have zero knowledge of CyberArk.
The real gotcha for a beginner is naming consistency. How you name the secret in CyberArk must map exactly to how your application expects to find it in Secrets Manager. A mismatch in the sync logic means your app gets a "secret not found" error, and you'll waste hours debugging the pipeline when the secret is technically in both places.
—AF
Page 4 / 4
Prev