Skip to main content
Version: 0.9.17-patch1

Platform TLS materials

Path: /admin-settingsPlatform Settings tab → Platform Secrets section

Platform Secrets store operator-managed credentials and TLS materials. Metadata lives in Postgres; secret values live in AWS Secrets Manager. The secrets grid is embedded at the bottom of the Platform settings tab.

LLM keys (openaiDefaultKey, azureDefaultKey) copied to new teams on creation are configured here with purpose LLM API key / Azure API key. Operators must Set Secret before autopopulate can copy values — see Team default secrets.

List columns

ColumnDescription
KeyUnique identifier (monospace, lowercase).
PurposeCA_CERT / CLIENT_CERT / CLIENT_KEY / TLS_SERVER_CERT / TLS_SERVER_KEY.
DescriptionOptional notes.
UpdatedLast modification.
ActionsEdit, Set Secret, Delete.

Fields

FieldRequiredDescription
KeyYesLowercase + digits + underscores. Immutable.
PurposeYesCA_CERT / CLIENT_CERT / CLIENT_KEY / TLS_SERVER_CERT / TLS_SERVER_KEY. Immutable.
DescriptionNoNotes.

Set Secret

The PEM content is managed via the Set Secret action:

FieldRequiredDescription
Secret ValueYesPEM-encoded cert or key.
Confirm ValueYesMust match.

PEM content is stored in AWS Secrets Manager and never displayed in the UI after saving.

Workflows

Add a CA certificate

  1. Click Create.
  2. Key: e.g. twilio_ca_cert.
  3. Purpose: CA_CERT.
  4. Description: e.g. "Twilio carrier CA".
  5. Save.
  6. Set Secret → paste PEM → confirm.

Add a client certificate + key for mTLS

  1. Create one material with Purpose CLIENT_CERT; set its PEM.
  2. Create another with Purpose CLIENT_KEY; set its PEM.
  3. In SIP Trunks, reference the CA in TLS CA Certificate, enable Require Client Certificate, and configure Peer Name Verification as needed.

Add edge TLS certificate material

v0.9.15 uses platform-secret purposes for public API/TelPro edge TLS automation:

  1. Create a material with Purpose TLS_SERVER_CERT; set the PEM full-chain certificate.
  2. Create a matching material with Purpose TLS_SERVER_KEY; set the PEM private key.
  3. Let the EDGE_TLS_RENEW / SERVICE_CONFIG_REFRESH jobs roll the decoded EDGE_TLS_* values to API and TelPro services, or follow the operator runbook for manual secret population.

Use these purposes for platform-owned public listeners. Continue using CA_CERT, CLIENT_CERT, and CLIENT_KEY for SIP trunk mTLS.

Version history

Platform secrets are included in whole-platform backups and full restores (registry metadata only — values stay in AWS Secrets Manager), but individual secret slots have no per-row history. There is no History action and no per-row version sidebar.

See also