Unable to get secrets in Vault subfolders from Spring Cloud Config Server (with Git and Vault backends)

Viewed 184

Context

We are currently using SCCS with Git and Vault for central config and secrets. The git repo and vault structure is flat. Each file is named for the application and environment, e.g. search-api-dev.properties in git & search-api-dev in the secrets backend in vault.

We want to organize this better, either:
by environment:

.
├── dev
│   └── search-api-dev.properties
│   └── user-api-dev.properties
├── stage
│   └── search-api-stage.properties
│   └── user-api-stage.properties
...

or by application:

.
├── search-api
│   └── search-api-dev.properties
│   └── search-api-stage.properties
├── user-api
│   └── user-api-dev.properties
│   └── user-api-stage.properties
...

In our Spring Cloud Config Server's src/main/resources/application.yaml I was able to get access to the environment subfolder using searchPaths, but am not able to get the secrets in the same location from vault:

spring:
  profiles:
    active: git, vault
  cloud:
    config:
      server:
        git:
          uri: git@domain.com:orgName/config/sccs.git
          searchPaths: '{profile}'
          order: 2
          ignoreLocalSshSettings: true
          privateKey: *private_key
        vault:
          host: vault.domain.com
          port: 443
          scheme: https
          defaultKey: '{profile}'
          order: 1
          kvVersion: 2
          authentication: token

Key Question

How can we get our SCCS to look inside the subfolders, similar to the searchPaths git option, and if not, what structure should we use to organize better?

Additional info:

  • We are using the default vault helm chart.
  • We are using a minimally customized configuration-service from this spring guide
0 Answers
Related