All Products
Search
Document Center

Bastionhost:Import ECS secrets from KMS

Last Updated:Mar 31, 2026

Bastionhost integrates with Key Management Service (KMS) to let you import Elastic Compute Service (ECS) secrets directly into Bastionhost. Once imported and authorized, Bastionhost users can log on to ECS instances without entering passwords.

Supported versions

Enterprise Edition and SM Edition.

Note

If your Bastionhost instance is Basic Edition, upgrade it first. For more information, see Upgrade instance type.

Prerequisites

Before you begin, ensure that you have:

Import KMS secrets

  1. Log on to the Bastionhost system. For more information, see Log on to the system.

  2. In the left-side navigation pane, choose Assets > Hosts.

  3. Find the host and click Import KMS Secret in the Actions column.

  4. In the Import KMS Secret dialog box, select the ECS secrets to import and click Import.

After the import completes, click the host name to open the Host Account tab, where you can view and manage the imported secrets.

Manage imported secrets

On the Host Account tab, perform any of the following operations on imported ECS secrets.

Delete ECS secrets

Select one or more ECS secrets and delete them. Deleting a secret removes it from Bastionhost only — the secret remains in KMS.

Note

After deleting an ECS secret from KMS, the ECS secret in your bastion host is marked as deleted and cannot be used.

Restrict access to SFTP only

Turn on Enable Only SFTP Permission for an account to disable SSH-based logon for that account.

What's next

To let Bastionhost users log on to ECS instances using the imported secrets, grant them the necessary permissions: