3 ms·
We're using Vault to create ephemeral database credentials for our services that are rotated every other hour, for that use case envs are not even viable becaus
by denvrede 4y ago
We're using Vault to create ephemeral database credentials for our services that are rotated every other hour, for that use case envs are not even viable because they're injected at startup and then never again.
- ianpurton 4y agoSo how do you get the pods to read the new credentials?
- falcolas 4y agoThe pods would have to either read directly from Vault, or a k8s controller which has vault access. In big brain fashion, one could also hard fail on a db auth failure so new pods - with the new secrets - can be spun up.