KMSインスタンスのSDKクライアントが初期化されると、クライアントからGetSecretValue操作を呼び出して、シークレット値を取得できます。 このトピックでは、この取得プロセスのコード例を示します。
完全なコード例
操作を呼び出して、シークレット値を取得します。
ソースコードGitHubリンク: GetSecretValue.php
コード例分析
クライアントを初期化
クライアントの初期化の詳細については、「クライアントの初期化」をご参照ください。
<?php
use AlibabaCloud\Dkms\Gcs\Sdk\Client as AlibabaCloudDkmsGcsSdkClient;
use AlibabaCloud\Dkms\Gcs\OpenApi\Models\Config as AlibabaCloudDkmsGcsOpenApiConfig;
function getDkmsGcsSdkClient()
{
global $clientKeyContent, $password, $endpoint;
// Construct the KMS instance SDK client configuration
$config = new AlibabaCloudDkmsGcsOpenApiConfig();
// The connection protocol. Set the value to https. The KMS instance service only allows access through the HTTPS protocol.
$config->protocol = 'https';
// Client Key.
$config->clientKeyContent = $clientKeyContent;
// Client Key security token.
$config->password = $password;
// The endpoint of your KMS instance. Set the value in the following format: <ID of your KMS instance >.cryptoservice.kms.aliyuncs.com.
$config->endpoint = $endpoint;
// Instance CA certificate
$config->caFilePath = 'path/to/caCert.pem';
// Construct the KMS instance SDK client object
return new AlibabaCloudDkmsGcsSdkClient($config);
}GetSecretValue操作を呼び出して、シークレット値を取得します。
function getSecretValueSample(){
global $client, $secretName;
// Construct a request to obtain credentials
$getSecretValueRequest = new GetSecretValueRequest([
'secretName' => $secretName,
]);
// Ignore the server certificate
$runtimeOptions = new RuntimeOptions();
//$runtimeOptions->ignoreSSL = true;
try {
// Call the operation to obtain credentials
$getSecretValueResponse = $client->getSecretValueWithOptions($getSecretValueRequest, $runtimeOptions);
// Credential name
$_secretName = $getSecretValueResponse->secretName;
// Credential value
$_secretData = $getSecretValueResponse->secretData;
var_dump($getSecretValueResponse->toMap());
} catch (\Exception $error) {
if ($error instanceof \AlibabaCloud\Tea\Exception\TeaError) {
var_dump($error->getErrorInfo());
}
var_dump($error->getMessage());
var_dump($error->getTraceAsString());
}
}