hashicorp / hashicorp/consul

ACL Token "Last Used" Time

Open
#7,181 0 comments 10 reactions 0 assignees View on GitHub
theme/acls theme/api type/enhancement type/umbrella-☂️
Dominant language
Go
Stars
30.1k
Forks
4.6k
Avg merge
2d 6h
Merged PRs (30d)
43

Description

#### Feature Description

It would be very helpful to have some information around when ACL tokens have been used for API access. Specifically when the token as last been used.

#### Use Case(s)

When rotating ACL tokens (and deprecating/deleting an old one), there is no easy way to determine if a token is no longer being used before deleting it. Currently, we are just setting all of the policies on the token to `deny` and hoping nothing breaks. A "LastUsed" time would go a long way to increasing confidence and safety when rotating production-used ACL tokens.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.