VTA management

Operational tasks for a running VTA: control who has access, retrieve secrets for services at runtime, rotate credentials, and protect against data loss with backup and restore.

Keeping a VTA running means handling day-two operations: granting and revoking access as your team changes, delivering credentials to services without hardcoding them, rotating a compromised key, and recovering from data loss. Getting these wrong can lock out a service, leave a credential over-exposed, or lose state you cannot rebuild.

The guides in this section cover the pnm CLI commands for each task, grouped by area: access and keys, secrets, credential lifecycle, and resilience. Most of these operations run against a live VTA. Rotating a credential means restarting the service that holds it, and a restore restarts the VTA. Start with Grant and revoke access if you need to grant or revoke access.

Prerequisites: these guides assume you already have a running VTA and the pnm CLI installed and connected as an admin. Some tasks, such as creating a top-level context, changing audit retention, or exporting and importing a backup, need a super-admin, and each guide lists what it needs. If you haven’t set up a VTA yet, start with Quickstart.