kedacore/keda

Hashicorp vault auth allow tokens directly set in TriggerAuthentication

Aperta

#6026 aperta il 2 ago 2024

 (4 commenti) (0 reazioni) (0 assegnatari)Go (1457 fork)auto 404
authbuggood first issuehelp wantedsecurity

Metriche repository

Star
 (10.372 stelle)
Metriche merge PR
 (Metriche PR in attesa)

Descrizione

Report

Currently, hashicorp vault auth supports 2 login methods, one based on service account and other based on tokens. The problem is that the token isn't provided from a secret but from the TriggerAuthentication directly. This is a security risk as TriggerAuthentication isn't a sensitive API by design: image image

Expected Behavior

The token should be recovered from a secret

Actual Behavior

The token is read from the TriggerAuthentication manifest

Guida contributor