Spring cloud vault not reloading/reflecting updates to secret value

Viewed 417

Spring cloud vault picks up the latest secret value during application start. If the secret is updated when the application is already up and running, then it is not picked up.

I understand this is a Spring config limitation and there are workaround with @RefreshScope annotation and explicitly invoking the /actuator/refresh API.

Is there any other mechanism where the application can listen to secret update notification and automate the refresh?

From the debug logs, i see that spring cloud vault return updated secret with the GET call based on "min-renewal" time.

Thanks

1 Answers

Got 'refresh' working with:

@Autowired
ContextRefresher contextRefresher;
public void refreshContext() {
    contextRefresher.refresh();
}

I am still trying to understand why spring cloud vault invokes vault login and Get API every 10 seconds if the refresh is not automated.

Related