Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

agent/template: add static_secret_render_interval configurable #11934

Merged
merged 10 commits into from
Jun 24, 2021

Conversation

jasonodonnell
Copy link
Contributor

@jasonodonnell jasonodonnell commented Jun 23, 2021

Consul Template recently added a feature to allow operators to override the default lease duration when a secret has no lease/isn't renewable. This default (5m) can be now altered using the following agent config:

template_config {
    static_secret_render_interval = 60
}

We'll need to add this configurable to both Vault K8s and Vault Helm.

@jasonodonnell jasonodonnell added this to the 1.8 milestone Jun 23, 2021
@jasonodonnell jasonodonnell requested review from tvoran, calvn, tomhjp and a team June 23, 2021 20:05
@vercel vercel bot temporarily deployed to Preview – vault June 23, 2021 20:07 Inactive
@vercel vercel bot temporarily deployed to Preview – vault-storybook June 23, 2021 20:07 Inactive
@jasonodonnell
Copy link
Contributor Author

In case it confuses anyone, consul-template is already updated in main so I did not need to update the dependency for this feature.

@vercel vercel bot temporarily deployed to Preview – vault-storybook June 23, 2021 21:12 Inactive
@vercel vercel bot temporarily deployed to Preview – vault June 23, 2021 21:12 Inactive
Copy link
Member

@tvoran tvoran left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you update the docs here too?

command/agent/config/config.go Outdated Show resolved Hide resolved
command/agent/template/template.go Outdated Show resolved Hide resolved
changelog/11934.txt Outdated Show resolved Hide resolved
website/content/docs/agent/template-config.mdx Outdated Show resolved Hide resolved
@vercel vercel bot temporarily deployed to Preview – vault-storybook June 24, 2021 18:20 Inactive
@vercel vercel bot temporarily deployed to Preview – vault June 24, 2021 18:20 Inactive
Co-authored-by: Theron Voran <[email protected]>
@vercel vercel bot temporarily deployed to Preview – vault-storybook June 24, 2021 18:21 Inactive
@vercel vercel bot temporarily deployed to Preview – vault June 24, 2021 18:21 Inactive
Copy link
Member

@tvoran tvoran left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Also a reminder to update the PR description with the new parameter 😃

@jasonodonnell jasonodonnell changed the title agent/template: add default_lease_duration configurable agent/template: add static_secret_render_interval configurable Jun 24, 2021
@jasonodonnell jasonodonnell merged commit 22d8470 into main Jun 24, 2021
@jasonodonnell jasonodonnell deleted the consul-template-lease-duration branch June 24, 2021 19:40
@@ -119,7 +119,9 @@ type Sink struct {

// TemplateConfig defines global behaviors around template
type TemplateConfig struct {
ExitOnRetryFailure bool `hcl:"exit_on_retry_failure"`
ExitOnRetryFailure bool `hcl:"exit_on_retry_failure"`
StaticSecretRenderIntRaw interface{} `hcl:"static_secret_render_interval"`
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Did we land/agree on settling with nonleased_secret_render_interval as the param name?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants