HashiCorp Vault
Required attributes
- Vault Url — the Vault server URL (e.g.,
https://vault.example.com:8200).
- Namespace (optional, Vault Enterprise) — the Vault namespace used for
all list/read calls. Leave blank for standard (non-namespaced) Vault.
Secrets are read from the fixed secret KV mount — there is no Mount
Path or KV Version attribute. Polysync tries the KV v2 engine first and
falls back to KV v1 automatically, so both engine versions work without
configuration.
Authentication methods
- Token — Vault Url, Token. Simplest; tokens are short-lived and
must be renewed.
- App Role ⭐ (recommended for machine-to-machine) — Vault Url,
Role Id, Secret Id. Designed for non-human callers; supports CIDR
binding and TTL controls.
- Username/Password — Vault Url, Username, Password. Use only when
integrating with an existing LDAP / userpass backend.
Permissions checklist
- Attach a Vault policy granting
read on secret/data/<secret-path>
for KV v2 (or secret/<secret-path> for KV v1) — Polysync always uses the
fixed secret mount.
- For App Role, bind the role to the policy and set conservative TTLs.