docs/doc/source/usertasks/kubernetes/kubernetes-user-tutorials-vault-overview.rst
Keane Lim 21b11b47d6 OpenStack VNF Integration User Tasks
Completed review comments
Minor abbreviation fix
Moved topics into its own VNF Integration section
Fixed abbreviations
Re-organized Kubernetes topics

Change-Id: I8940d3572b789990d3b5f2d201f8ec8a46ce2943
Signed-off-by: Keane Lim <keane.lim@windriver.com>
2021-03-23 11:10:42 -04:00

1.2 KiB

Vault Overview

You can optionally integrate open source Vault secret management into the solution. The Vault integration requires PVC (Persistent Volume Claims) as a storage backend to be enabled.

There are two methods for using Vault secrets with hosted applications:

  1. Have the application be Vault Aware and retrieve secrets using the Vault REST API. This method is used to allow an application write secrets to Vault, provided the applicable policy gives write permission at the specified Vault path. For more information, see Vault Aware <vault-aware>.
  2. Have the application be Vault Unaware and use the Vault Agent Injector to make secrets available on the container filesystem. For more information, see, Vault Unaware <vault-unaware>.

Both methods require appropriate roles, policies and auth methods to be configured in Vault.