-
Notifications
You must be signed in to change notification settings - Fork 4.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vault agent doesn’t respect the number of retries #15725
Comments
This may have been fixed by #15204, available in Vault 1.11.0. |
Thank you. I'll test it and let you know. |
Hi @jasonodonnell, Unless I'm missing something the issue still persist: / $ vault version
Vault v1.11.1 (0f634755745f4adf62ec0723a0b93d6dce5bc33e), built 2022-07-19T20:16:47Z
/ $ cat /vault/config.json | grep -A 6 vault\":
"vault": {
"address": "https://vault.service.intra:8200",
"retry": [
{
"num_retries": "3"
}
]
/ $ cat /vault/config.json | grep -A 5 template_config
"template_config": [
{
"error_on_missing_key": false,
"exit_on_retry_failure": false
}
],
/ $ Logs:
|
I will take a closer look, but unfortunately the retry logic is complicated due to the interaction of sub systems in agent as per the documentation: https://www.vaultproject.io/docs/agent#retry-stanza |
I did find this note in the code for template: vault/command/agent/template/template.go Line 267 in 637d4bd
|
Hi there! I'm pretty sure my PR #16970 will fix this issue. To describe the current behaviour: the issue was that when caching was enabled, configured retries were not respected. If This issue should be resolved soon and fixed in 1.12.0. Thanks for the report! |
Hi there! I'm going to close this issue as I just merged #16970 which should fix the issue identified here. It should now respect the number of retries in all cases, regardless of if caching is enabled. This should release in 1.12. Thanks for the bug report! |
Describe the bug
Looks like the Vault agent doesn’t respect the number of retries.
I also tried setting the
VAULT_MAX_RETRIES
ENV variable.To Reproduce
Steps to reproduce the behavior:
Please see the configuration in the environment section below.
Expected behavior
According to the docs, I expect that the Vault agent won’t exit on an error and that the number of retries will be three. This is what I’m getting:
I tried to set the VAULT_MAX_RETRIES ENV variable but no luck.
There is an option to pass the Consul template retry config but the problem is that I don’t understand how to pass it from the Vault config.
This is the Consul template config for the Vault config shown below:
I can tell that the config is being parsed properly, because if I pass two values in the retry stanza I got an error that only one is allowed.
Environment:
vault status
):1.10.1
vault version
):1.10.3
Vault agent configuration file(s):
Additional context
Add any other context about the problem here.
The text was updated successfully, but these errors were encountered: