feat: set max token life for auth_kubernetes_role

found kubernetes vaultauth resources never picking up new policies,
because they would infinitely renew their token.

- set default max token length for roles to 1 day
- changed all existing role token_max_ttl to match their token_ttl
This commit is contained in:
2026-02-22 22:28:21 +11:00
parent c94b2af196
commit 7cafafd483
13 changed files with 18 additions and 0 deletions
+1
View File
@@ -92,6 +92,7 @@ module "auth_kubernetes_role" {
bound_service_account_names = each.value.bound_service_account_names
bound_service_account_namespaces = each.value.bound_service_account_namespaces
token_ttl = each.value.token_ttl
token_max_ttl = each.value.token_max_ttl
token_policies = var.policy_auth_map[each.value.backend][each.value.role_name]
audience = each.value.audience