Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vault token rotation may not be right #91

Open
suprjinx opened this issue Nov 19, 2024 · 0 comments
Open

Vault token rotation may not be right #91

suprjinx opened this issue Nov 19, 2024 · 0 comments
Assignees

Comments

@suprjinx
Copy link
Collaborator

suprjinx commented Nov 19, 2024

Astral assumes it's started with a very powerful vault token (such as root) and then rotates to a more limited token.

I don't think this is quite right, since if vault is started with an already-limited token, it may not be able to rotate itself. Also, the policy we create and apply at rotation should always be applied whether or not the token is rotated.

@suprjinx suprjinx self-assigned this Nov 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant