Protecting test assets by using secrets

Secrets are key-value pairs that are created for your project in HCL DevOps Test Hub (Test Hub) under a security group. You can create security group for your project that enable you or members in your project to use secrets at test runtime either in Test Hub or in HCL DevOps Test Integrations and APIs (Test Integrations and APIs).
The secrets in a project in Test Hub maintains a separate access control list managed by the members with access to the secrets added to the security group. Controlling access to secrets means controlling access to applications and systems under test. The introduction of secrets under security group for a project simplifies managing access to separate environments. If a member of a project does not have access to a secret, for example, a server credential then the member cannot accidentally or intentionally run tests against that server. For example, tests that must access the database server by using the server credentials to retrieve stored data can only be run by a member if the access to the secrets is granted.
Note:
Secrets are applicable to server test assets created in Test Hub and test assets created in Test Integrations and APIs that facilitates running tests in defined environments. Secrets are not applicable to tests created in Test UI or Test Performance.

As a project member with the Owner or Tester role, you can add secrets to the security group in the project. You can grant or restrict access to the secrets that you added to the security group in the project.

Members with access to a secret security group can access, edit, or delete the secrets in Test Hub and can view secrets, edit secrets, or delete secrets.

Members are granted Read access to the security group at the role level, while Read and Write access can be provided to specific members.

Promoted test variables from server test assets can be mapped to secret-backed values by using security groups and secret entries. This mapping helps you reuse secure values across environments without embedding credentials directly in test steps.

Members in the project with the Owner or Tester role and with access to the secrets can use the secrets in tests at runtime.

If you are configuring a project to run an API Suite with tests that refer to secret values, you must configure the secrets under a security group by using the Add Secret option in the Security page. You must complete the following tasks:
  1. Create a security group. See Creating a security group.
  2. Add secrets in the security group. See Creating a secret in a security group.
  3. Grant access to project members or member roles, who can access the secrets. See Granting access to members or member roles.