Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support Revoking Vault Token on Pod Termination #65

Closed
lawliet89 opened this issue Feb 4, 2020 · 0 comments · Fixed by #67
Closed

Support Revoking Vault Token on Pod Termination #65

lawliet89 opened this issue Feb 4, 2020 · 0 comments · Fixed by #67
Labels
enhancement New feature or request injector Area: mutating webhook service

Comments

@lawliet89
Copy link
Contributor

lawliet89 commented Feb 4, 2020

This is related to hashicorp/vault#6492

Currently, in my (manual) sidecars for Vault Agents, I add a preStop hook to revoke the Vault token on pod termination.

        lifecycle:
          preStop:
            exec:
              command:
              - /bin/sh
              - -c
              - /bin/sleep 10 && /bin/vault token revoke -self

This example requires that the Vault token be written to $HOME/.vault-token too.

@tvoran tvoran added enhancement New feature or request injector Area: mutating webhook service labels Feb 4, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request injector Area: mutating webhook service
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants