UNCLASSIFIED - NO CUI

Resolve "Support Short Term SA Tokens"

General MR

Summary

Remove token_reviewer_jwt and kubernetes_ca_cert from our auth init commands, so Vault auto-supports K8s service account short-lived tokens. See upstream documentation here for more details: https://developer.hashicorp.com/vault/docs/auth/kubernetes#kubernetes-1-21

Relevant logs/screenshots

Current Vault -- upgrading 0.31.0-bb.1 --> 0.31.0-bb.3 and bouncing both vault-vault-0 and prometheus-monitoring-monitoring-kube-prometheus-0

image

upgrading 0.31.0-bb.1 --> 0.31.0-bb.4 and re-setting auth -- we can bounce the pods multiple times -- no issues:

image

Working in umbrella clean / upgrade now

image

Linked Issue

issue

Upgrade Notices

An upgrade notice was added to the Umbrella MR.

Edited by Michael Martin

Merge request reports

Loading