-
Feature Request
-
Resolution: Unresolved
-
Undefined
-
None
-
2.4
-
False
-
-
False
- What is the nature and description of the request?
The "HashiCorp Vault Secret Lookup" option for Credentials within AAP does not meet the security requirements of the organization. The recommendation from HashiCorp is that AAP should support authenticating to Vault for secret access using OpenID Connect and/or JWT:
https://developer.hashicorp.com/vault/api-docs/auth/jwt
2. Why does the customer need this? (List the business requirements here)
Enhanced Security requirement.
Currently, to fully support what Hashi can provide, the Customer must code this individually for each playbook/template Whilst this is possible, it's hard to audit and control.
- duplicates
-
AAPRFE-1645 Ability to use AAP OIDC for authentication by 3rd party (e.g. Hashi Vault)
-
- Backlog
-