mattcasters opened a new pull request, #8305: URL: https://github.com/apache/hop/pull/8305
The HashiCorp Vault (and OpenBAO) variable resolver can now authenticate with a Kubernetes ServiceAccount JWT instead of a long-lived Vault token. Addresses #8302 ### What changed - New `TOKEN` / `KUBERNETES` authentication type on `BaseVaultVariableResolver`. Existing metadata without the field still uses `TOKEN`. - Kubernetes options: role, JWT file path (default `/var/run/secrets/kubernetes.io/serviceaccount/token`, read with HopVfs), optional inline JWT, optional auth mount (default `kubernetes`). - After Kubernetes login the short-lived Vault token is cached in memory, renewed when Vault says it is renewable, and replaced by a fresh login when it expires. It is never stored in metadata. - The editor groups Connection / Authentication / Secrets and only shows the fields that apply to the selected auth type. ### Tests - Unit tests for auth-type parsing, JWT loading, path prefix, and client cache. - UI tests for widget visibility per auth type. - Testcontainers IT against Vault 1.19 with a TokenReview mock (inline JWT, JWT file, custom mount, cache, token regression, failure cases). - Hop docker integration tests: `main-0004-kubernetes-auth` plus the existing vault suite. ------------------------ Thank you for your contribution! Follow this checklist to help us incorporate your contribution quickly and easily: - [x] Run `mvn clean install apache-rat:check` to make sure basic checks pass. A more thorough check will be performed on your pull request automatically. - [x] If you have a group of commits related to the same change, please squash your commits into one and force push your branch using `git rebase -i`. - [x] Mention the appropriate issue in your description (for example: `addresses #123`), if applicable. To make clear that you license your contribution under the [Apache License Version 2.0, January 2004](http://www.apache.org/licenses/LICENSE-2.0) you have to acknowledge this by using the following check-box. - [x] I hereby declare this contribution to be licensed under the [Apache License Version 2.0, January 2004](http://www.apache.org/licenses/LICENSE-2.0) - [ ] In any other case, please file an [Apache Individual Contributor License Agreement](https://www.apache.org/licenses/icla.pdf). -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
