hashicorp / hashicorp/vault-secrets-operator

Artificial delay for eventually consistent secrets

Open
#271 3 comments 1 reaction 0 assignees View on GitHub
enhancement
Dominant language
Go
Stars
600
Forks
146
Avg merge
3d 8h
Merged PRs (30d)
6

Description

**Is your feature request related to a problem? Please describe.**
Some secrets (ie, AWS IAM) are eventually consistent and require a delay before they can be used.

**Describe the solution you'd like**
A method to introduce a delay before VSO writes secrets to Kubernetes

**Describe alternatives you've considered**
It may be possible to get the pods that consume VSO secrets to have a delay before attempting to use their secrets, but then logic needs to be build into each application. It may make sense for VSO to handle this delay, as it a central service/tool.

**Additional context**
To quote:
https://developer.hashicorp.com/vault/docs/secrets/aws#usage
> Unfortunately, IAM credentials are eventually consistent with respect to other Amazon services. If you are planning on using these credential in a pipeline, you may need to add a delay of 5-10 seconds (or more) after fetching credentials before they can be used successfully.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.