HashiCorp Vault Provider for Secret Store CSI Driver
OTHER License
Bot releases are visible (Hide)
Published by hc-github-team-es-release-engineering 2 months ago
FEATURES:
-log-level
flag. [GH-295]CHANGES:
Published by hc-github-team-es-release-engineering 4 months ago
CHANGES:
Published by hc-github-team-es-release-engineering 7 months ago
CHANGES:
Published by hc-github-team-es-release-engineering 12 months ago
Published by hc-github-team-es-release-engineering over 1 year ago
CHANGES:
tokenRequests
--set tokenRequests[0].audience="vault"
. See-hmac-secret-name
IMPROVEMENTS:
Published by hc-github-team-es-release-engineering almost 2 years ago
CHANGES:
Published by hc-github-team-es-release-engineering about 2 years ago
CHANGES:
BUGS:
VAULT_ADDR
environment variable can now be used to set the Vault address. [GH-160]IMPROVEMENTS:
Published by hc-github-team-es-release-engineering over 2 years ago
IMPROVEMENTS:
-vault-namespace
-vault-tls-ca-cert
-vault-tls-ca-directory
-vault-tls-server-name
-vault-tls-client-cert
-vault-tls-client-key
-vault-tls-skip-verify
audience
to customize the aud
claim in the JWT [GH-144]filePermission
can be used per-secret to set the file permissions it is written with. [GH-139]Published by hc-github-team-es-release-engineering over 2 years ago
-write-secrets
flag removed. All secrets are now written to the filesystem by the CSI secrets store driver. [GH-133]
-health_addr
flag removed, use -health-addr
instead. [GH-133]kubernetesServiceAccountPath
and vaultCAPem
are used. [GH-134]Published by hc-github-team-es-release-engineering almost 3 years ago
-write-secrets
flag now defaults to false
, delegating file writes to the driver. [GH-127]
-write-secrets
is deprecated and will be removed in the next major version.secretKey
in the SecretProviderClass [GH-126]amd64
, arm64
, arm/v6
and 386
Published by tomhjp over 3 years ago
--write-secrets=false
will become the default from v0.4.0, and requires secrets-store-csi-driver v0.0.21+.--health_addr
flag is marked deprecated but still functioning. Please use --health-addr
instead. --health_addr
is currently planned for removal in v0.5.0.--write-secrets=false
[GH-89]
--write-secrets=false
will become the default from v0.4.0 and require secrets-store-csi-driver v0.0.21+--health_addr
flag is marked deprecated and replaced by --health-addr
. Slated for removal in v0.5.0 [GH-100]Published by tomhjp over 3 years ago
objects
entryarray
entry under objects
objectVersion
is now ignoredobjectPath
is renamed to secretPath
secretKey
, secretArgs
and method
are newly available optionsobjectName
no longer determines which key is read from the secret's datasecretKey
is set, that is the key from the secret's data that will be writtensecretKey
is not set, the whole JSON response from Vault will be writtenvaultSkipTLSVerify
is no longer required to be set to "true"
if the vaultAddress
scheme is not https
spec.parameters.kubernetesServiceAccountPath
is now ignored and will log a warning if setspec.parameters.vaultCAPem
is now ignored and will log a warning if set. This is a breaking change
spec.parameters.vaultTLSClientCertPath
and spec.parameters.vaultTLSClientKeyPath
are newly available optionsPublished by tomhjp over 3 years ago
CHANGES:
--grpcSupportedProviders
.Published by tomhjp almost 4 years ago
Set GOOS and GOARCH for Makefile build target (#52)
Enforce descending directory write path (#50)