Fabian Grosch created NIFI-16431:
------------------------------------

             Summary: Allow HashiCorp Vault Parameter Provider to list secrets 
under a path prefix
                 Key: NIFI-16431
                 URL: https://issues.apache.org/jira/browse/NIFI-16431
             Project: Apache NiFi
          Issue Type: Improvement
            Reporter: Fabian Grosch


The HashiCorpVaultParameterProvider lists secrets from the root of the 
configured Key/Value Secrets Engine before applying the Secret Name Pattern 
filter.
The pattern controls which secrets are read, but it does not limit which paths 
NiFi lists in Vault.

In a shared Vault, each team may only have access to its own folder.
With these permissions, parameter fetching or provider verification can fail 
because NiFi tries to list the engine root or folders the team cannot access.
Granting wider list access to work around this goes against least privilege and 
may reveal names of unrelated secrets and folders.

Add an optional Secret Path Prefix property, relative to the configured engine 
mount.
For example, with Key/Value Path set to 'kv' and Secret Path Prefix set to 
'nested/path', NiFi lists secrets starting at that path and searches its 
subfolders.
This lets the provider work with Vault policies that only allow access to one 
folder and its subfolders.

When the prefix is not set, the provider keeps its current behavior and lists 
from the engine root.
The feature supports KV v1 and KV v2, and the Secret Name Pattern continues to 
filter which listed secrets are read.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to