Fabian Grosch created NIFI-16431:
------------------------------------
Summary: Allow HashiCorp Vault Parameter Provider to list secrets
under a path prefix
Key: NIFI-16431
URL: https://issues.apache.org/jira/browse/NIFI-16431
Project: Apache NiFi
Issue Type: Improvement
Reporter: Fabian Grosch
The HashiCorpVaultParameterProvider lists secrets from the root of the
configured Key/Value Secrets Engine before applying the Secret Name Pattern
filter.
The pattern controls which secrets are read, but it does not limit which paths
NiFi lists in Vault.
In a shared Vault, each team may only have access to its own folder.
With these permissions, parameter fetching or provider verification can fail
because NiFi tries to list the engine root or folders the team cannot access.
Granting wider list access to work around this goes against least privilege and
may reveal names of unrelated secrets and folders.
Add an optional Secret Path Prefix property, relative to the configured engine
mount.
For example, with Key/Value Path set to 'kv' and Secret Path Prefix set to
'nested/path', NiFi lists secrets starting at that path and searches its
subfolders.
This lets the provider work with Vault policies that only allow access to one
folder and its subfolders.
When the prefix is not set, the provider keeps its current behavior and lists
from the engine root.
The feature supports KV v1 and KV v2, and the Secret Name Pattern continues to
filter which listed secrets are read.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)