feat(tools): implement ENABLE_VAULT_OPERATIONS to gate mutating tools - #126
feat(tools): implement ENABLE_VAULT_OPERATIONS to gate mutating tools#126artfaal wants to merge 1 commit into
Conversation
Implements the documented but previously unimplemented ENABLE_VAULT_OPERATIONS env var. All tools were registered unconditionally, so a read-only deployment still exposed write_secret/delete_secret/create_mount and PKI-write tools. Now mutating tools register only when ENABLE_VAULT_OPERATIONS=true; default is read-only (list/read for KV, mounts and PKI).
|
Thank you for your submission! We require that all contributors sign our Contributor License Agreement ("CLA") before we can accept the contribution. Read and sign the agreement Learn more about why HashiCorp requires a CLA and what the CLA includes Max Solovev seems not to be a GitHub user. Have you signed the CLA already but the status is still pending? Recheck it. |
1 similar comment
|
Thank you for your submission! We require that all contributors sign our Contributor License Agreement ("CLA") before we can accept the contribution. Read and sign the agreement Learn more about why HashiCorp requires a CLA and what the CLA includes Max Solovev seems not to be a GitHub user. Have you signed the CLA already but the status is still pending? Recheck it. |
Что в форке: два патча поверх upstream main (метаданные KV v2 в read_secret, рабочий ENABLE_VAULT_OPERATIONS с read-only дефолтом), ссылки на upstream PR hashicorp#125/hashicorp#126, сборка образа через release-default в Nexus (тег 0.2.0-jd-ro1) и деплой на gvm25. В штатный README добавлен указатель на README-JD.
Контрибьютить в hashicorp дорого по бюрократии — решение принято, план «примет upstream — свернём форк» больше не действует. Ветки pr/* остаются как способ держать патч отдельно от JD-специфики, PR hashicorp#125 и hashicorp#126 висят с прежнего захода.
Problem
The security model docs recommend setting
ENABLE_VAULT_OPERATIONS=false"if write access isn't needed", but the variable is not implemented —InitToolsregisters every tool unconditionally, so a read-only deployment still exposeswrite_secret,delete_secret,create_mount,delete_mountand the PKI-write tools.Change
Implement the documented flag. Mutating tools (write/delete/create + PKI enable/issue) register only when
ENABLE_VAULT_OPERATIONS=true. Default is read-only:list_mounts,list_secrets,read_secret, plus PKI reads.Why it matters
Operators with read-only use cases can now actually restrict the tool surface, matching what the security-model documentation already promises.