hashicorp / hashicorp/vault-helm

AWSKMS Seal support AWS Identity and Access Management Roles Anywhere

Open
#900 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Shell
Stars
1.3k
Forks
898
Avg merge
3d 1h
Merged PRs (30d)
1

Description

Our Requirement is to use awskms seal type for auto-unseal HashiCorp Vault deployed on OCP containers.

One way is to provided IAM credentials in AWSKMS stanza but that is forbidden in my organization.

Does vault also support AWS Identity and Access Management Roles Anywhere mechanism to obtain credentials and then use it for auto-unsealing?
Vault use official AWS SDK so looks like its possible, but we dont know how to achieve the same.

Could you please help us in this regards.

Contributor guide

Open the contributing guide

Research direction

Review the AWSKMS stanza and the described OCP deployment context first. Determine whether AWS Identity and Access Management Roles Anywhere is supported for auto-unsealing, and define the required chart or configuration changes if it is not. Done should include a documented, reproducible way to use the mechanism or a clear statement of its scope.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws
Domain
cloud, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.