cosign
cosign copied to clipboard
[Vault KMS] don't assume the `transit` path
Description
currently cosing assumes that the transit secret engine will be mounted at the transit
path all of the times.
This is not the case for Vault. The mount path should be explicit in the kms URL.
Hi, I guess can find the solution here > https://docs.sigstore.dev/cosign/kms_support/#hashicorp-vault
@raffaelespazzoli Indeed, you can find how to point to the transit path, as @hasanhakkaev mentioned above.
Not much of a news for this particular case but, here is the "transit" secret engine hardcoded