Using PHP SDK
The Kron PAM PHP SDK provides a secure and efficient way to integrate Kron PAM Vault credential management directly into PHP-based applications. It allows applications and automation scripts to dynamically retrieve and rotate privileged credentials, eliminating the need to store static passwords in source code or configuration files.
The SDK communicates through the Kron PAM Secrets Management Agent, which acts as a secure intermediary between the application and the Kron PAM Vault. This integration supports modern PHP environments (PHP 8.1 and later) and can be deployed on both Linux and Windows platforms.
Integration Steps
- Add the Kron PAM PHP SDK package.
- Include the Composer autoloader in your PHP script.
require __DIR__ . '/vendor/autoload.php';- Ensure network connectivity between the application environment and the Kron PAM Secrets Management Agent and/or Kron PAM Password Vault.
Example Implementation
Below is a sample PHP script that demonstrates how to connect to the Kron PAM Secret Management Agent and/or Kron PAM Vault and then retrieve credentials from the Vault.
<?php
require __DIR__ . '/vendor/autoload.php';
use Krontechnology\AapmPhpSdk\PasswordManager;
use Krontechnology\AapmPhpSdk\Intercept\DirectHttpInterceptor;
use Com\Kron\Aapm\Rpc\ValidResponseType;
// Initialize the Password Manager instance
$passwordManager = PasswordManager::instanceWithServer('localhost', 8080);
$passwordManager->httpAddress('https://10.20.42.121');
echo "PasswordManager instantiated.\n";
try {
// Retrieve password with parameters
$result = $passwordManager->getPasswordWithParams(
'testaccount',
'9920067c-a5c9-428c-85bc-50894cb51adf',
'/LinuxTest',
[
'comment' => 'Test comment',
'showUserName' => true,
'passwordChangeRequired' => true,
'responseType' => ValidResponseType::TEXT,
'prettify' => true,
'passwdExpirationInMinutes' => '5',
'tenantId' => 'host'
]
);
// Response handling
if ($result->hasError()) {
echo "Error: " . $result->getErrValue() . "\n";
echo "Error Code: " . $result->getFailMode() . "\n";
} else {
echo PasswordManager instantiated.
Success: [username: aioc, password: 9Hg2kLm3T]
Process finished with exit code 0Success: " . $result->getValue() . "\n";
}
} catch (Exception $e) {
echo "An error occurred: " . $e->getMessage() . "\n";
}When executed successfully, the SDK returns live credentials from the Kron PAM Vault:
PasswordManager instantiated.
gRPC call completed with status code: 0
Success: 3XpZR9erConfiguration Parameters
Before retrieving any credentials from the Kron PAM Vault, your application must establish a secure connection to the Kron PAM Secrets Management Agent and/or define the Kron PAM Vault server address.
$passwordManager = PasswordManager::instanceWithServer('AgentIPAddress', AgentPort);
$passwordManager->httpAddress('https://KronPAMIPAddress');Parameter | Description |
|---|---|
AgentIPAddress | Kron PAM Secrets Manager Agent IP Address (hostname) |
AgentPort | Kron PAM Secrets Manager Agent Port |
KronPAMIPAddress | Defines the HTTPS endpoint of the Kron PAM Vault itself — where the SDK will direct API requests to retrieve credentials or rotate passwords. |
The primary SDK function used to retrieve credentials from the Kron PAM Vault is:
getPasswordWithParams(
string $accountName,
string $accountToken,
string $accountPath,
array $options = []
)This method securely requests and retrieves the password (and optionally the username) for a managed account in Kron PAM Vault via the configured Kron PAM Secrets Management Agent and/or Kron PAM Vault.
Parameter | Definition |
|---|---|
$accountToken | Kron PAM AAPM token assigned for account |
$accountName | Account name registered in Kron PAM Vault |
$accountPath | Account path within the Vault (e.g., /Databases/SharedAccouts, /Windows) |
comment | Optional descriptive comment for the fetching password |
showUserName | Include username in response (true/false) |
passwdExpirationInMinutes | Duration before password expiration (in minutes) |
passwordChangeRequired | Whether to force a new password rotation upon retrieval |
prettify | Enables formatted response output |
tenantId | Specifies the tenant or logical domain when working in multi-tenant environments. Ensures credentials are retrieved from the correct scope. |
responseType | Format of the response (Text, Json) |