Skip to content

Hashicorp Vault AppRole with SOPS #695

Open
@nxzqio

Description

@nxzqio

In this documentation the only available authentication is a Vault Token.

The issue with a Vault Token is it's intended to be short-lived, it can be renewed but by an outside process which is harder at scale.

Ideally we should be able to use the Vault AppRole Engine, so we pass in a Role-ID and a Secret-ID (Normally as a secret), which is used to obtain a short lived token for the transaction.

Documentation

Vault AppRole

Flux with SOPs and Hashicorp Vault

external-secrets.io using AppRole authentication with Vault

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/sopsSOPS related issues and pull requestsenhancementNew feature or requesthelp wantedExtra attention is needed

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions