[
https://issues.apache.org/jira/browse/NIFI-16431?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Pierre Villard reassigned NIFI-16431:
-------------------------------------
Assignee: Fabian Grosch
> Allow HashiCorp Vault Parameter Provider to list secrets under a path prefix
> ----------------------------------------------------------------------------
>
> Key: NIFI-16431
> URL: https://issues.apache.org/jira/browse/NIFI-16431
> Project: Apache NiFi
> Issue Type: Improvement
> Reporter: Fabian Grosch
> Assignee: Fabian Grosch
> Priority: Minor
> Time Spent: 20m
> Remaining Estimate: 0h
>
> The HashiCorpVaultParameterProvider lists secrets from the root of the
> configured Key/Value Secrets Engine before applying the Secret Name Pattern
> filter.
> The pattern controls which secrets are read, but it does not limit which
> paths NiFi lists in Vault.
> In a shared Vault, each team may only have access to its own folder.
> With these permissions, parameter fetching or provider verification can fail
> because NiFi tries to list the engine root or folders the team cannot access.
> Granting wider list access to work around this goes against least privilege
> and may reveal names of unrelated secrets and folders.
> Add an optional Secret Path Prefix property, relative to the configured
> engine mount.
> For example, with Key/Value Path set to 'kv' and Secret Path Prefix set to
> 'nested/path', NiFi lists secrets starting at that path and searches its
> subfolders.
> This lets the provider work with Vault policies that only allow access to one
> folder and its subfolders.
> When the prefix is not set, the provider keeps its current behavior and lists
> from the engine root.
> The feature supports KV v1 and KV v2, and the Secret Name Pattern continues
> to filter which listed secrets are read.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)