namespace GB5Shared.Vault { /// /// Vault authentication methods supported by . /// Only is implemented today; the others are modeled for future providers /// registered via . /// public enum VaultAuthMethod { Token, AppRole, Kubernetes } /// /// Strongly typed configuration for the GB5 Vault integration. /// Bound from the "Vault" configuration section. All values should come from /// appsettings.json or environment variables (e.g. Vault__Address, /// Vault__Token) — never hardcode Vault addresses or tokens in source. /// public class VaultOptions { public const string SectionName = "Vault"; /// Base URL of the Vault server, e.g. "http://127.0.0.1:8200". public string Address { get; set; } = string.Empty; /// KV v2 secrets engine mount point. public string MountPoint { get; set; } = "secret"; /// Vault Enterprise namespace, if applicable. public string? Namespace { get; set; } public VaultAuthMethod AuthMethod { get; set; } = VaultAuthMethod.Token; /// Required when is . public string? Token { get; set; } /// Reserved for the future AppRole auth provider. public string? RoleId { get; set; } /// Reserved for the future AppRole auth provider. public string? SecretId { get; set; } /// Reserved for the future Kubernetes auth provider. public string? KubernetesRole { get; set; } /// Reserved for the future Kubernetes auth provider. public string KubernetesJwtPath { get; set; } = "/var/run/secrets/kubernetes.io/serviceaccount/token"; /// Timeout for Vault API calls. public int RequestTimeoutSeconds { get; set; } = 10; /// Maximum retry attempts for transient Vault failures. public int RetryMaxAttempts { get; set; } = 3; /// Base delay for exponential backoff between retries. public int RetryBaseDelayMilliseconds { get; set; } = 250; /// Sliding TTL for the in-process secret cache. public int CacheTtlSeconds { get; set; } = 300; } }