vault-unseal icon indicating copy to clipboard operation
vault-unseal copied to clipboard

feature: support kubernetes proxy verb

Open M0NsTeRRR opened this issue 1 year ago • 0 comments

✨ Describe the feature you'd like

It would be cool to have the possibility to pass a kubeconfig and use kubernetes proxy verb. It will allow to unseal a kubernetes vault HA cluster from non kubernetes nodes.

🌧 Is your feature request related to a problem?

If you want to run an HA vault cluster exposed only in the cluster.

🔎 Describe alternatives you've considered

  • Exposing each pod with an ingress (I don't like the idea to expose something that is not needed).
  • Install vault-unseal in the cluster, I don't like the idea to run this software in the same cluster as my vault cluster. For example a compromise node (with a SSH key) can result in discovering vault unseal keys and secret in one time.

⚠ If implemented, do you think this feature will be a breaking change to users?

No

⚙ Additional context

No response

🤝 Requirements

  • [X] I have confirmed that someone else has not submitted a similar feature request.
  • [X] If implemented, I believe this feature will help others, in addition to solving my problems.
  • [X] I have looked into alternative solutions to the best of my ability.
  • [X] (optional) I would be willing to contribute to testing this feature if implemented, or making a PR to implement this functionality.

M0NsTeRRR avatar Jan 09 '24 22:01 M0NsTeRRR