Skip to content

HC Vault: add allowlist support for acceptable HC Vault URLs#2164

Merged
felixfontein merged 4 commits intogetsops:mainfrom
felixfontein:hv
May 3, 2026
Merged

HC Vault: add allowlist support for acceptable HC Vault URLs#2164
felixfontein merged 4 commits intogetsops:mainfrom
felixfontein:hv

Conversation

@felixfontein
Copy link
Copy Markdown
Contributor

Default is all, which is the current behavior. When SOPS_HC_VAULT_ALLOWLIST is set to none or a comma-separated list of prefixes, none or only URLs starting with these prefixes are allowed.

@felixfontein felixfontein requested a review from a team April 29, 2026 19:04
Comment thread hcvault/keysource.go
Signed-off-by: Felix Fontein <felix@fontein.de>
Signed-off-by: Felix Fontein <felix@fontein.de>
Signed-off-by: Felix Fontein <felix@fontein.de>
Signed-off-by: Felix Fontein <felix@fontein.de>
Copy link
Copy Markdown
Contributor

@sabre1041 sabre1041 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Thanks for taking a look at adding the / to the vault address

@felixfontein felixfontein merged commit a5fd438 into getsops:main May 3, 2026
16 checks passed
@felixfontein felixfontein deleted the hv branch May 3, 2026 18:08
@felixfontein
Copy link
Copy Markdown
Contributor Author

@sabre1041 thanks for reviewing!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants