Open blmhemu opened 1 year ago
Hi @blmhemu thanks for reporting this! It looks like this is a bug in the hvac
library instead, and I've opened an issue for it here:
@blmhemu I have a PR up in hvac
that should fix this:
In the meantime if you want to see if that fixes it with ansible as well, you can try installing hvac
from my branch:
pip install https://github.com/briantist/hvac/archive/auth.token.create/wrapped-role-based.tar.gz
This should work with no changes to Ansible/this collection.
SUMMARY
The template
{{ lookup('community.hashi_vault.vault_token_create', url='https://100.72.58.16:8200/', wrap_ttl='1m', role_name='cluster-pki') }}
does NOT create a wrapped token - just creates a normal token.The equivalent cli command works fine with the same token (as above)
vault token create -wrap-ttl=1m -role=cluster-pki
and creates a wrapped token.ISSUE TYPE
COMPONENT NAME
community.hashi_vault.vault_token_create
ANSIBLE VERSION
COLLECTION VERSION
OS / ENVIRONMENT
MacOS
STEPS TO REPRODUCE
EXPECTED RESULTS
It creates a wrapped token.
ACTUAL RESULTS
It creates a normal token (not wrapped).