[
https://issues.apache.org/jira/browse/NIFI-16431?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18123880#comment-18123880
]
ASF subversion and git services commented on NIFI-16431:
--------------------------------------------------------
Commit 1644ae795e6ec95402a83346b2c0974b543fb395 in nifi's branch
refs/heads/main from Fabian Grosch
[ https://gitbox.apache.org/repos/asf?p=nifi.git;h=1644ae795e6 ]
NIFI-16431 Allow HashiCorp Vault Parameter Provider to list secrets under a
path prefix (#11763)
> Allow HashiCorp Vault Parameter Provider to list secrets under a path prefix
> ----------------------------------------------------------------------------
>
> Key: NIFI-16431
> URL: https://issues.apache.org/jira/browse/NIFI-16431
> Project: Apache NiFi
> Issue Type: Improvement
> Reporter: Fabian Grosch
> Priority: Minor
> Time Spent: 20m
> Remaining Estimate: 0h
>
> The HashiCorpVaultParameterProvider lists secrets from the root of the
> configured Key/Value Secrets Engine before applying the Secret Name Pattern
> filter.
> The pattern controls which secrets are read, but it does not limit which
> paths NiFi lists in Vault.
> In a shared Vault, each team may only have access to its own folder.
> With these permissions, parameter fetching or provider verification can fail
> because NiFi tries to list the engine root or folders the team cannot access.
> Granting wider list access to work around this goes against least privilege
> and may reveal names of unrelated secrets and folders.
> Add an optional Secret Path Prefix property, relative to the configured
> engine mount.
> For example, with Key/Value Path set to 'kv' and Secret Path Prefix set to
> 'nested/path', NiFi lists secrets starting at that path and searches its
> subfolders.
> This lets the provider work with Vault policies that only allow access to one
> folder and its subfolders.
> When the prefix is not set, the provider keeps its current behavior and lists
> from the engine root.
> The feature supports KV v1 and KV v2, and the Secret Name Pattern continues
> to filter which listed secrets are read.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)