namespace GB5Shared.Vault
{
///
/// Vault authentication methods supported by .
/// Only is implemented today; the others are modeled for future providers
/// registered via .
///
public enum VaultAuthMethod
{
Token,
AppRole,
Kubernetes
}
///
/// Strongly typed configuration for the GB5 Vault integration.
/// Bound from the "Vault" configuration section. All values should come from
/// appsettings.json or environment variables (e.g. Vault__Address,
/// Vault__Token) — never hardcode Vault addresses or tokens in source.
///
public class VaultOptions
{
public const string SectionName = "Vault";
/// Base URL of the Vault server, e.g. "http://127.0.0.1:8200".
public string Address { get; set; } = string.Empty;
/// KV v2 secrets engine mount point.
public string MountPoint { get; set; } = "secret";
/// Vault Enterprise namespace, if applicable.
public string? Namespace { get; set; }
public VaultAuthMethod AuthMethod { get; set; } = VaultAuthMethod.Token;
/// Required when is .
public string? Token { get; set; }
/// Reserved for the future AppRole auth provider.
public string? RoleId { get; set; }
/// Reserved for the future AppRole auth provider.
public string? SecretId { get; set; }
/// Reserved for the future Kubernetes auth provider.
public string? KubernetesRole { get; set; }
/// Reserved for the future Kubernetes auth provider.
public string KubernetesJwtPath { get; set; } = "/var/run/secrets/kubernetes.io/serviceaccount/token";
/// Timeout for Vault API calls.
public int RequestTimeoutSeconds { get; set; } = 10;
/// Maximum retry attempts for transient Vault failures.
public int RetryMaxAttempts { get; set; } = 3;
/// Base delay for exponential backoff between retries.
public int RetryBaseDelayMilliseconds { get; set; } = 250;
/// Sliding TTL for the in-process secret cache.
public int CacheTtlSeconds { get; set; } = 300;
}
}