Use the PASM CLI create-box command to create a box in your Cryptographic Security Platform Vault for Secrets.

Syntax

pasmcli create-box [options]

Option

Description

-h or --help

Displays usage text.

-d or --description string

Short description for the box. Strings must be enclosed in double quotes.

-x or --exclusive-checkout string {enable|disable}

If this flag is set, all secret checkouts will be exclusive, and only one user can check out the secret at a time.

Important: If this property is set in a secret, it takes precedence over the property being set in a box.

-l or --lease-duration string

The lease duration to enforce for all secrets that are checked out from a box. The duration must be in ISO 8601 format. For example, P1M15DT12H30M.

Important: If this property is set in a secret, it takes precedence over the property being set in a box.

-L or --lease-renewable string {enable|disable}

Reserved for future use.

-m or --max-secret-versions int

The maximum number of secrets versions to persist in integer format.

-n or --name string

The name of the box. Strings must be enclosed in double quotes.

-r or --rotation-duration string

The duration for when secrets in the box will be rotated. The behavior depends on the rotation-force option. The duration must be in ISO 8601 format. For example, P1M15DT12H30M.

Important: If this property is set in a secret, it takes precedence over the property being set in a box.

-f or --rotation-force string {enable|disable}

If this flag is set, it forces the rotation of all secrets in the box. The behavior varies depending on the rotation-duration and rotation-on-checkin options.

Important: If this property is set in a secret, it takes precedence over the property being set in a box.

-o or --rotation-on-checkin string {enable|disable}

If this flag is set, the secret will be automatically rotated upon checkin. If the checkout lease expires, then the behavior depends on the rotation-force option.

-D or --secret-duration string

The expiration duration for secrets in the box, if the expires-at option is not provided with the create-secret command. The duration must be in ISO 8601 format. For example, P1M15DT12H30M. Strings must be enclosed in double quotes.

-t or --tagkey stringArray

The tag key to associate with the box. This option is repeatable.

-v or --tagvalue stringArray

The tag value to associate with the box. This option is repeatable.