Open tgross opened 4 years ago
Alternately, now that we'll have Variables in Nomad 1.4.0, we could let users get secrets from there.
Note for implementation: one of the things we deliberately did with Task Access to Variables was to prefix the task variables path with nomad/jobs
, leaving room for us to do something like nomad/volumes
in the future. We could automatically grant claims access to secrets that match the volume name in the same way we've done with the tasks. You'd register the secrets at the time the volume is created/registered, and from there on out you wouldn't need to know about secrets. This is a much simpler solution than Vault access.
I need this :)
In https://github.com/hashicorp/nomad/pull/7923 we added support for including secrets for volume registration, which are then passed along to plugin RPCs. If we could source these secrets from Vault, that would be even better.
cc @schmichael @dadgar