Skip to main content
The Encrova SQL Server secret rotation allows you to automatically rotate your database users’ passwords at a predefined interval.

Prerequisites

  1. Create two SQL Server logins and database users with the required permissions. We’ll refer to them as user-a and user-b.
  2. Create another SQL Server login with permissions to alter logins for user-a and user-b. We’ll refer to this as the admin login.
Here’s how to set up the prerequisites:
To learn more about SQL Server’s permission system, please visit this documentation.

How it works

  1. Encrova connects to your database using the provided admin login credentials.
  2. A random value is generated and the password for user-a is updated with the new value.
  3. The new password is then tested by logging into the database.
  4. If test is successful, it’s saved to the output secret mappings so that rest of the system gets the newly rotated value(s).
  5. The process is then repeated for user-b on the next rotation.
  6. The cycle repeats until secret rotation is deleted/stopped.

Rotation Configuration

1

Open Secret Rotation Page

Head over to Secret Rotation configuration page of your project by clicking on Secret Rotation in the left side bar
2

Click on Microsoft SQL Server card

3

Provide the inputs

string
required
SQL Server admin username
string
required
SQL Server admin password
string
required
SQL Server host url (e.g., your-server.database.windows.net)
number
required
Database port number (default: 1433)
string
required
Database name (default: master)
string
required
The first login name to rotate - user-a
string
required
The second login name to rotate - user-b
string
Optional database certificate to connect with database
4

Configure the output secret mapping

When a secret rotation is successful, the updated values needs to be saved to an existing key(s) in your project.
string
required
The environment where the rotated credentials should be mapped to.
string
required
The secret path where the rotated credentials should be mapped to.
number
required
What interval should the credentials be rotated in days.
string
required
Select an existing secret key where the rotated database username value should be saved to.
string
required
Select an existing select key where the rotated database password value should be saved to.

FAQ

When a system has multiple nodes by horizontal scaling, redeployment doesn’t happen instantly.This means that when the secrets are rotated, and the redeployment is triggered, the existing system will still be using the old credentials until the change rolls out.To avoid causing failure for them, the old credentials are not removed. Instead, in the next rotation, the previous user’s credentials are updated.
The admin account is used by Encrova to update the credentials for user-a and user-b.You don’t need to grant all permissions for your admin account but rather just the permission to alter logins (ALTER ANY LOGIN).
When using Azure SQL Database, you’ll need to:
  1. Use the full server name as your host (e.g., your-server.database.windows.net)
  2. Ensure your admin account is either the Azure SQL Server admin or an Azure AD account with appropriate permissions
  3. Configure your Azure SQL Server firewall rules to allow connections from Encrova’s IP addresses