mattcasters opened a new pull request, #8305:
URL: https://github.com/apache/hop/pull/8305

   The HashiCorp Vault (and OpenBAO) variable resolver can now authenticate 
with a Kubernetes ServiceAccount JWT instead of a long-lived Vault token.
   
   Addresses #8302
   
   ### What changed
   - New `TOKEN` / `KUBERNETES` authentication type on 
`BaseVaultVariableResolver`. Existing metadata without the field still uses 
`TOKEN`.
   - Kubernetes options: role, JWT file path (default 
`/var/run/secrets/kubernetes.io/serviceaccount/token`, read with HopVfs), 
optional inline JWT, optional auth mount (default `kubernetes`).
   - After Kubernetes login the short-lived Vault token is cached in memory, 
renewed when Vault says it is renewable, and replaced by a fresh login when it 
expires. It is never stored in metadata.
   - The editor groups Connection / Authentication / Secrets and only shows the 
fields that apply to the selected auth type.
   
   ### Tests
   - Unit tests for auth-type parsing, JWT loading, path prefix, and client 
cache.
   - UI tests for widget visibility per auth type.
   - Testcontainers IT against Vault 1.19 with a TokenReview mock (inline JWT, 
JWT file, custom mount, cache, token regression, failure cases).
   - Hop docker integration tests: `main-0004-kubernetes-auth` plus the 
existing vault suite.
   
   ------------------------
   
   Thank you for your contribution! Follow this checklist to help us 
incorporate your contribution quickly and easily:
   - [x] Run `mvn clean install apache-rat:check` to make sure basic checks 
pass. A more thorough check will be performed on your pull request 
automatically.
   - [x] If you have a group of commits related to the same change, please 
squash your commits into one and force push your branch using `git rebase -i`.
   - [x] Mention the appropriate issue in your description (for example: 
`addresses #123`), if applicable.
   
   To make clear that you license your contribution under the [Apache License 
Version 2.0, January 2004](http://www.apache.org/licenses/LICENSE-2.0)
   you have to acknowledge this by using the following check-box.
   
   - [x] I hereby declare this contribution to be licensed under the [Apache 
License Version 2.0, January 2004](http://www.apache.org/licenses/LICENSE-2.0)
   - [ ] In any other case, please file an [Apache Individual Contributor 
License Agreement](https://www.apache.org/licenses/icla.pdf).


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to