Class VaultKeyValueSecretStore

  • All Implemented Interfaces:
    SecretStore<Secret>

    public class VaultKeyValueSecretStore
    extends Object
    A secret store that fetches secrets from a Hashicorp Vault server, using version 2 of the key-value backend. This backend allows storing arbitrary data as secrets, while also allowing versioning of those secrets. We make use of the versioning capability to allow secret rotation - the latest version is always the active secret, while previous versions are valid until they are destroyed.
    • Field Detail

      • DEFAULT_PATH

        public static final String DEFAULT_PATH
        The default path at which this secret engine is mounted by Vault.
        See Also:
        Constant Field Values
    • Method Detail

      • refresh

        public void refresh()
        Description copied from interface: SecretStore
        Indicates that the store should refresh its secrets from the backing storage mechanism. This can be used to cause reload of a store after a secret rotation if the backend does not automatically detect such changes. Refresh may be an asynchronous operation and no guarantees are made about when clients of this secret store may see updated secrets after a call to refresh.
        Specified by:
        refresh in interface SecretStore<Secret>
      • getStoredType

        public Class<T> getStoredType()
        Description copied from interface: SecretStore
        The top-level class that this store is capable of storing. This is a reification of the type parameter and can be used to lookup stores for a given type.
        Specified by:
        getStoredType in interface SecretStore<T extends Secret>
        Returns:
        the top-most type that this store is capable of storing, typically either CryptoKey for key-stores, GenericSecret for password stores, or Secret if the store is capable of storing any type of secret.
      • getActive

        public <S extends T> Promise<S,​NoSuchSecretException> getActive​(Purpose<S> purpose)
        Description copied from interface: SecretStore
        Returns the active secret for the given purpose.
        Specified by:
        getActive in interface SecretStore<T extends Secret>
        Type Parameters:
        S - the type of secret.
        Parameters:
        purpose - the purpose for which a secret is required.
        Returns:
        the active secret from this store.
      • getValid

        public <S extends T> Promise<Stream<S>,​NeverThrowsException> getValid​(Purpose<S> purpose)
        Description copied from interface: SecretStore
        Returns all valid secrets for the given purpose from this store.
        Specified by:
        getValid in interface SecretStore<T extends Secret>
        Type Parameters:
        S - the type of secret.
        Parameters:
        purpose - the purpose.
        Returns:
        a stream of all valid secrets of the given type from this store, or an empty stream if none exist.