-
Story
-
Resolution: Done
-
Critical
-
None
-
1
-
False
-
None
-
False
-
SECFLOWOTL-113 - Enable Rotation for Storage URL and Vault Token Secret for Tekton Chains
-
Allow supplying MONGO_SERVER_URL via chains-config to facilitate rotation
-
-
-
10
-
Pipelines Sprint TekShift 1, Pipelines Sprint TekShift 2, Pipelines Sprint TekShift 3, Pipelines Sprint TekShift 4, Pipelines Sprint Pioneers 6, Pipelines Sprint Pioneers 7, Pipelines Sprint Pioneers 8, Pipelines Sprint Pioneers 9, Pipelines Sprint Pioneers 10, Pipelines Sprint Pioneers 11, Pipelines Sprint Pioneers 12
- Allow supplying a token path besides a token in the Chains config, maybe something like `signers.kms.kmsref.auth.tokenpath` (???). This allows mounting the token inside the Chains controller and having it read from that path, instead of supplying in the config directly.
- this also applies to rotating the mongo server URL as well
- is documented by
-
RHDEVDOCS-5985 DOC: Integrate Chains with Hashicorp Vault
- Closed
- is related to
-
SRVKP-6630 add upstream tests for mongo and vault
- To Do