Hashicorp vault auth allow tokens directly set in TriggerAuthentication #6026
Labels
bug
Something isn't working
good first issue
Good for newcomers
help wanted
Looking for support from community
security
All issues related to security
Report
Currently, hashicorp vault auth supports 2 login methods, one based on service account and other based on tokens.
The problem is that the token isn't provided from a secret but from the TriggerAuthentication directly. This is a security risk as TriggerAuthentication isn't a sensitive API by design:
Expected Behavior
The token should be recovered from a secret
Actual Behavior
The token is read from the TriggerAuthentication manifest
The text was updated successfully, but these errors were encountered: