Skip to content

Allow differently named KV engine paths and a top level secret directory other than vaultPass -- Or drop the requirement entirely and have vaultPass dynamicly scan for kv engines and secret paths at user login? #31

@ipaqmaster

Description

@ipaqmaster

Is your feature request related to a problem? Please describe.
A clear and concise description of what the problem is. Ex. I'm always frustrated when [...]

When we have existing kv secret engines for our organisazation and now need to consider migrating every single website credential set to a new kv engine named secret and under a subpath named vaultPass

Describe the solution you'd like
It would be outstanding if vaultPass simply has an extra text field, maybe under its options tab underneath the Auth Mountpoint string, asking for the kv engine name to use and optionally also the top level secret path to use.

Describe alternatives you've considered
A clear and concise description of any alternative solutions or features you've considered.

Automatic scanning of all KV secret paths a user has access to when they click Login to Vault, instead of requiring secret/vaultPass to exist

Additional context
Add any other context or screenshots about the feature request here.

I understand at a glance this is a pretty tall order; I hope at least adding text fields to overwrite the kv/ engine path name and /vaultPass top level directory name requirement inside would not be too difficult.

Replacing this entire system with a dynamic kv engine and inside path scan at user login would be a lot more and different work, but would also help this project flourish in any environment.

(Considered adding /totp support as well?)

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions