[ 
https://issues.apache.org/jira/browse/NIFI-16431?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Pierre Villard resolved NIFI-16431.
-----------------------------------
    Fix Version/s: 2.13.0
       Resolution: Fixed

> Allow HashiCorp Vault Parameter Provider to list secrets under a path prefix
> ----------------------------------------------------------------------------
>
>                 Key: NIFI-16431
>                 URL: https://issues.apache.org/jira/browse/NIFI-16431
>             Project: Apache NiFi
>          Issue Type: Improvement
>            Reporter: Fabian Grosch
>            Assignee: Fabian Grosch
>            Priority: Minor
>             Fix For: 2.13.0
>
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> The HashiCorpVaultParameterProvider lists secrets from the root of the 
> configured Key/Value Secrets Engine before applying the Secret Name Pattern 
> filter.
> The pattern controls which secrets are read, but it does not limit which 
> paths NiFi lists in Vault.
> In a shared Vault, each team may only have access to its own folder.
> With these permissions, parameter fetching or provider verification can fail 
> because NiFi tries to list the engine root or folders the team cannot access.
> Granting wider list access to work around this goes against least privilege 
> and may reveal names of unrelated secrets and folders.
> Add an optional Secret Path Prefix property, relative to the configured 
> engine mount.
> For example, with Key/Value Path set to 'kv' and Secret Path Prefix set to 
> 'nested/path', NiFi lists secrets starting at that path and searches its 
> subfolders.
> This lets the provider work with Vault policies that only allow access to one 
> folder and its subfolders.
> When the prefix is not set, the provider keeps its current behavior and lists 
> from the engine root.
> The feature supports KV v1 and KV v2, and the Secret Name Pattern continues 
> to filter which listed secrets are read.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to