#vault (2020-06)

vault Discussions related to Hashicorp Vault

2020-06-25

2020-06-10

David avatar
David

I’m looking to start using the database secrets engine to create creds for my postgres RDS db.

How does Vault handle queries that are already running with old credentials when the rotation happens?

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)

Both sets of credentials are valid for an overlapping period of time

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)

That way you can gracefully handle rotations

David avatar
David

Excellent. Do you know if that time limit is configurable?

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)

No… but someone here probably does!

Yonatan Koren avatar
Yonatan Koren

@David you probably figured this out two weeks ago but there is a default TTL and a maximum TTL. If you don’t specify the TTL as a secret consumer you will get the default. If you do specify the TTL, you can do that all the way up to the max TTL.

    keyboard_arrow_up