Uploaded image for project: 'Ansible Automation Platform RFEs'
  1. Ansible Automation Platform RFEs
  2. AAPRFE-1020

enable authenticating to Vault for secrets access using OpenID Connect and/or JWT

XMLWordPrintable

    • False
    • Hide

      None

      Show
      None
    • False

      1. What is the nature and description of the request? 

      The "HashiCorp Vault Secret Lookup" option for Credentials within AAP does not meet the security requirements of the organization. The recommendation from HashiCorp is that AAP should support authenticating to Vault for secret access using OpenID Connect and/or JWT:

      https://developer.hashicorp.com/vault/api-docs/auth/jwt

      2. Why does the customer need this? (List the business requirements here)
      Enhanced Security requirement.
      Currently, to fully support what Hashi can provide, the Customer must code this individually for each playbook/template Whilst this is possible, it's hard to audit and control.

              bcoursen@redhat.com Brian Coursen
              rhn-support-rpu Rui Pu
              Votes:
              5 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated: