kedacore/keda
Hashicorp vault auth allow tokens directly set in TriggerAuthentication
Aperta
#6026 aperta il 2 ago 2024
authbuggood first issuehelp wantedsecurity
Metriche repository
- Star
- (10.372 stelle)
- Metriche merge PR
- (Metriche PR in attesa)
Descrizione
Report
Currently, hashicorp vault auth supports 2 login methods, one based on service account and other based on tokens.
The problem is that the token isn't provided from a secret but from the TriggerAuthentication directly. This is a security risk as TriggerAuthentication isn't a sensitive API by design:
Expected Behavior
The token should be recovered from a secret
Actual Behavior
The token is read from the TriggerAuthentication manifest