feat(kv): include KV v2 metadata (custom_metadata, version) in read_secret - #125
Open
artfaal wants to merge 1 commit into
Open
feat(kv): include KV v2 metadata (custom_metadata, version) in read_secret#125artfaal wants to merge 1 commit into
artfaal wants to merge 1 commit into
Conversation
The v2 read handler discarded secret.Data["metadata"] and returned only the
data payload, so clients could not see version, timestamps or custom_metadata
(e.g. description/usage). Return {data, metadata} instead, keeping the values
and surfacing the metadata block clients need to understand a secret.
|
Thank you for your submission! We require that all contributors sign our Contributor License Agreement ("CLA") before we can accept the contribution. Read and sign the agreement Learn more about why HashiCorp requires a CLA and what the CLA includes Max Solovev seems not to be a GitHub user. Have you signed the CLA already but the status is still pending? Recheck it. |
artfaal
pushed a commit
to artfaal/vault-mcp-server
that referenced
this pull request
Jul 21, 2026
Что в форке: два патча поверх upstream main (метаданные KV v2 в read_secret, рабочий ENABLE_VAULT_OPERATIONS с read-only дефолтом), ссылки на upstream PR hashicorp#125/hashicorp#126, сборка образа через release-default в Nexus (тег 0.2.0-jd-ro1) и деплой на gvm25. В штатный README добавлен указатель на README-JD.
artfaal
pushed a commit
to artfaal/vault-mcp-server
that referenced
this pull request
Aug 4, 2026
Контрибьютить в hashicorp дорого по бюрократии — решение принято, план «примет upstream — свернём форк» больше не действует. Ветки pr/* остаются как способ держать патч отдельно от JD-специфики, PR hashicorp#125 и hashicorp#126 висят с прежнего захода.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
read_secreton a KV v2 mount returns only the data payload (secret.Data["data"]) and discardssecret.Data["metadata"]. MCP clients therefore cannot see a secret's version, created/updated timestamps, or custom_metadata (e.g.description/usage) — even though Vault returns all of it in the same data-endpoint response.Change
Return
{"data": ..., "metadata": ...}for KV v2 reads, keeping the values while surfacing the metadata block. KV v1 behaviour is unchanged.Why it matters
Teams often store human context (what a secret is for, where it's used) in
custom_metadata. Without it an agent reading a secret has no idea what it is; this makes that context available.