HashiCorp Vault

Required attributes

  • Vault Url — the Vault server URL (e.g., https://vault.example.com:8200).
  • Namespace (optional, Vault Enterprise) — the Vault namespace used for all list/read calls. Leave blank for standard (non-namespaced) Vault.

Secrets are read from the fixed secret KV mount — there is no Mount Path or KV Version attribute. Polysync tries the KV v2 engine first and falls back to KV v1 automatically, so both engine versions work without configuration.

Authentication methods

  • Token — Vault Url, Token. Simplest; tokens are short-lived and must be renewed.
  • App Role ⭐ (recommended for machine-to-machine) — Vault Url, Role Id, Secret Id. Designed for non-human callers; supports CIDR binding and TTL controls.
  • Username/Password — Vault Url, Username, Password. Use only when integrating with an existing LDAP / userpass backend.

Permissions checklist

  • Attach a Vault policy granting read on secret/data/<secret-path> for KV v2 (or secret/<secret-path> for KV v1) — Polysync always uses the fixed secret mount.
  • For App Role, bind the role to the policy and set conservative TTLs.