f5-appsvcs-extension
f5-appsvcs-extension copied to clipboard
Local Credentials for targeted objects (WAF/Certs etc)
trafficstars
Is your feature request related to a problem?
We would like to use a local account on the BIG-IP to pull targetted resource objects.
Describe the solution you'd like
We would like to use a local account, something that "exists" in the BIG-IP, either from a Data Group or a local user account would be great. Another alternative would be a vault only accessible from the BIG-IP where the creds could be stored (there is integration happening for things like this with Azure Key Vault).
Describe alternatives you've considered
The only alternative is to "include" the credentials in the declaration or use a non-account-protected endpoint. Both solutions are hard to get past a security audit around automation and are non-starters.