Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document best-practices for minimal vault role configuration for istio-csr #130

Open
SpectralHiss opened this issue Feb 3, 2022 · 1 comment

Comments

@SpectralHiss
Copy link

When configuring a Vault issuer for istio-csr, the least privileged Vault role configurations are not very obvious.

We have been through this particular problem recently and can supply a quick guide around minimal policy for any PKI engine role that is dedicated to istio-csr cert issuance.

We could even show a fully worked example in kind in an examples/ directory under docs/ ?

@JoshuaFurman
Copy link

Would love to get some traction on this issue, is anyone from cert-manager handling issues on this repo?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants