Skip to content

Clarify Vault client vs server authentication #1580 - #3300

Open
AzazelSensei wants to merge 2 commits into
spring-cloud:mainfrom
AzazelSensei:docs-1580-vault-auth
Open

AzazelSensei wants to merge 2 commits into
spring-cloud:mainfrom
AzazelSensei:docs-1580-vault-auth

Conversation

@AzazelSensei

Copy link
Copy Markdown

The Vault pages still read as if every client must send a token. I spelled out the two modes: X-Config-Token per request vs server-side authentication, that spring-vault-core auto-configures the client from spring.cloud.config.server.vault properties, and that a server token is renewed when Vault marks it renewable.

Fixes #1580

Document when the client must send X-Config-Token, that Spring Vault
is auto-configured from server properties, and that server-side
tokens are renewed.

Fixes spring-cloudgh-1580

Signed-off-by: Abdullah <89297042+AzazelSensei@users.noreply.github.com>
[[vault-authentication]]
== Client and Server Authentication

There are two separate questions: how Config Server authenticates to Vault, and whether a Config Client must send a Vault token.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reword this to not ask questions. State there are two ways to authenticate.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reworded that to state there are two ways to authenticate.

Signed-off-by: Abdullah <89297042+AzazelSensei@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Enhance vault documentation

3 participants