CredHub Service Broker allows apps running on VMware Tanzu Application Service for VMs (TAS for VMs) to access secure credentials in CredHub.
Apps can use these credentials to authenticate with services not on TAS for VMs, including services running on Tanzu Operations Manager such as Spring Cloud Services and services external to Tanzu Operations Manager.
The CredHub Service Broker uses secure binding credentials to prevent credential exposure in the app environment.
The CredHub Service Broker registers a service broker with TAS for VMs and exposes its service plans on the Marketplace. Developers can then create service instances using Apps Manager or the Cloud Foundry Command Line Interface (cf CLI) and bind them to their apps.
Creating a CredHub Service Broker instance and binding it to an app creates a credential in CredHub and provides the reference to that credential in the app environment. This allows developers to deploy apps that can securely access credentials for services that are not running on TAS for VMs.
The key feature of CredHub Service Broker is secure access to service credentials for services that are not running on TAS for VMs.
The following table provides version and version-support information about the v1.6 release line of CredHub Service Broker.
Element | Details |
---|---|
Tile version | v1.6.4 |
Release date | July 29, 2024 |
Software component version | v1.6.4 |
Compatible Tanzu Operations Manager versions | 3.0 |
Compatible TAS for VMs versions | 4, 5, and 6 |
IaaS support | AWS, Azure, GCP, OpenStack, and vSphere |
IPsec support? | Yes |
The following table provides version and version-support information about the v1.5 release line of CredHub Service Broker.
Element | Details |
---|---|
Tile version | v1.5.5 |
Release date | February 20, 2024 |
Software component version | v1.5.5 |
Compatible Tanzu Operations Manager versions | 2.10, 3.0 |
Compatible TAS for VMs versions | 2.11, 2.13, 3, and 4 |
IaaS support | AWS, Azure, GCP, OpenStack, and vSphere |
IPsec support? | Yes |
CredHub Service Broker has the following requirement:
To enable secure binding credentials in runtime CredHub, see Securing Services Instance Credentials with Runtime CredHub.