Push out deprecation of Authentication Without Workload Identity
to 1.11 or further
#24970
Labels
Authentication Without Workload Identity
to 1.11 or further
#24970
Proposal
Push out deprecation of
Authentication Without Workload Identity
to 1.11, and/or until hashicorp/vault#29435 is addressed.Edit: there is precedent, it was originally scheduled for deprecation in 1.9 but it was pushed out.
Use-cases
I want to run my cluster in adherence with Hashicorp best practices, which necessitates the use of mutual TLS authentication, while also having Vault fetch required metadata from Nomad using said mutual TLS process.
Attempted Solutions
The alternatives presented require some Rube Goldberg-esque machinations that on a long enough timeline would fail and break JWT/OIDC trust between Nomad and vault.
The text was updated successfully, but these errors were encountered: