> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/resilience-testing/chaos-engineering/faults/chaos-fault-categories/cloud-foundry/shared/cf-and-bosh-secrets.md).

# Cf And Bosh Secrets

The following Cloud Foundry secrets reside on the same machine where the chaos infrastructure is executed. These secrets are provided in the `/etc/linux-chaos-infrastructure/cf.env` file in the following format:

```env
CF_API_ENDPOINT=XXXXXXXXXXXXXXXXXXX
CF_USERNAME=XXXXXXXXXXXXXXXXXXXXXXX
CF_PASSWORD=XXXXXXXXXXXXXXXXXXXXXXX
UAA_SERVER_ENDPOINT=XXXXXXXXXXXXXXX
BOSH_CLIENT=XXXXXXXXXXXXXXXXXXXXXXX
BOSH_CLIENT_SECRET=XXXXXXXXXXXXXXXX
BOSH_CA_CERT=XXXXXXXXXXXXXXXXXXXXXX
BOSH_ENVIRONMENT=XXXXXXXXXXXXXXXXXX
```

{% hint style="info" %}
If the secrets file is not provided, the secrets are attempted to be derived from environment variables and the config file by the fault-injector.
{% endhint %}

| ENV name              | Description                                                   | Example                           |
| --------------------- | ------------------------------------------------------------- | --------------------------------- |
| CF\_API\_ENDPOINT     | API endpoint for the CF setup                                 | `https://api.system.cf-setup.com` |
| CF\_USERNAME          | Username for the CF user                                      | `username`                        |
| CF\_PASSWORD          | Password for the CF user                                      | `password`                        |
| UAA\_SERVER\_ENDPOINT | API endpoint for the UAA server for the CF setup              | `https://uaa.system.cf-setup.com` |
| BOSH\_CLIENT          | Used by the `bosh` CLI, the BOSH client                       | `admin`                           |
| BOSH\_CLIENT\_SECRET  | Used by the `bosh` CLI, the BOSH client secret                | `UBu9Fu3oW35sO6fw12auPH76gsRTy7`  |
| BOSH\_CA\_CERT        | Used by the `bosh` CLI, the file path for BOSH CA certificate | `/root/root_ca_certificate`       |
| BOSH\_ENVIRONMENT     | Used by the `bosh` CLI, the BOSH environment                  | `bosh.corp.local`                 |

## Fault injector ENVs and config file <a href="#fault-injector-envs-and-config-file" id="fault-injector-envs-and-config-file"></a>

If `/etc/linux-chaos-infrastructure/cf.env` file is not provided, fault-injector attempts to derive the secrets from environment variables or a configuration file. Any secret that is re-declared will be overridden in the following order of decreasing precedence:

1. `/etc/linux-chaos-infrastructure/cf.env` file
2. Environment variables
3. Configuration file

The configuration file should be provided at `/etc/linux-chaos-infrastructure/cf-fault-injector.yaml`:

```yaml
cf-api-endpoint: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
username: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
password: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
uaa-server-endpoint: XXXXXXXXXXXXXXXXXXXXXXXXXX
bosh-client: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
bosh-client-secret: XXXXXXXXXXXXXXXXXXXXXXXXXXX
bosh-ca-cert: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
bosh-environment: XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
```

A mapping between all the three formats for providing the secrets is as follows:

| cf.env                | ENV                   | cf-fault-injector.yaml |
| --------------------- | --------------------- | ---------------------- |
| CF\_API\_ENDPOINT     | CF\_API\_ENDPOINT     | cf-api-endpoint        |
| CF\_USERNAME          | USERNAME              | username               |
| CF\_PASSWORD          | PASSWORD              | password               |
| UAA\_SERVER\_ENDPOINT | UAA\_SERVER\_ENDPOINT | uaa-server-endpoint    |
| BOSH\_CLIENT          | BOSH\_CLIENT          | bosh-client            |
| BOSH\_CLIENT\_SECRET  | BOSH\_CLIENT\_SECRET  | bosh-client-secret     |
| BOSH\_CA\_CERT        | BOSH\_CA\_CERT        | bosh-ca-cert           |
| BOSH\_ENVIRONMENT     | BOSH\_ENVIRONMENT     | bosh-environment       |
