kedacore/keda
Hashicorp vault auth allow tokens directly set in TriggerAuthentication
オープン
#6,026 opened on 2024/08/02
authbuggood first issuehelp wantedsecurity
Repository metrics
- Stars
- (10,372 個のスター)
- PR merge metrics
- (平均マージ 8d 8h) (30d で 94 merged PRs)
説明
Report
Currently, hashicorp vault auth supports 2 login methods, one based on service account and other based on tokens.
The problem is that the token isn't provided from a secret but from the TriggerAuthentication directly. This is a security risk as TriggerAuthentication isn't a sensitive API by design:
Expected Behavior
The token should be recovered from a secret
Actual Behavior
The token is read from the TriggerAuthentication manifest