Commit graph

1694 commits

Author SHA1 Message Date
Robert
5f078e2d39
Add chroot known-issue and sync activation-flag release note (#27558)
* Add chroot known-issue and activation-flag release note

* Fix reference link
2024-06-21 13:05:12 -05:00
Sarah Chavis
d23db14c46
[DOCS: SPE-827] Add autopilot known issue to 1.15 docs and 1.16/1.17 release notes (#27454)
* Update 1.15 docs with autopilot known issue

* add autopilot issue to 1.16 and 1.17 release notes as known issue
2024-06-20 10:48:30 -07:00
Jacob Henner
46a41a549b
Specify headers by environment variable (#21993)
* Specify headers by environment var

* Add changelog entry

* Add tests, docs

* Formatting

---------

Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>
2024-06-19 16:51:24 -04:00
Adrian Todorov
e7f2107b52
clarify the JWT auth bound_audiences change in behaviour (#27541) 2024-06-19 08:56:45 -05:00
John-Michael Faircloth
ab08d623e8
docs: add note to jwt auth for bound aud changes (#27530) 2024-06-19 08:35:22 -05:00
Violet Hynes
ff8442dff7
VAULT-28192 Add known issue for Agent/Proxy CPU issue (#27520)
* VAULT-28192 Add known issue for Agent/Proxy CPU issue

* Remove version column

* Add versions to other rows
2024-06-18 09:25:23 -04:00
Yoko Hyakuna
164352e5b4
Remove an extra space (#27508) 2024-06-14 14:14:35 -07:00
Sarah Chavis
7f0e64480f
[DOCS] Correct adaptive overload link (#27506) 2024-06-14 11:44:58 -07:00
Adam Rowan
52d35cdf65
Update configuration.mdx (#27497)
Adding SNMPv3 fields to credential resolver documentation.
2024-06-13 16:33:56 -07:00
Scott Miller
c131b47535
Link to the CLI commands in the BYOK pages (#27490) 2024-06-13 11:41:21 -05:00
Scott Miller
1a8e6791da
Update documentation to add the Transform import CLI command (#27487) 2024-06-13 11:35:39 -05:00
John-Michael Faircloth
377294fa76
docs: add link to jwt auth upgrade note for 1.16 (#27468) 2024-06-12 18:54:08 +00:00
John-Michael Faircloth
76ebf0b41b
docs: correct auth jwt role requirements (#27384)
* docs: correct auth jwt role requirements

* remove upgrade guide to be added in separate PR

* Revert "remove upgrade guide to be added in separate PR"

This reverts commit 6554d3ff63.

* update required details for bound audience

* Apply suggestions from code review

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* fix formatting to match the existing format of the file

* add 1.16 known issues

* add 1.17 upgrade guide note

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-06-12 13:46:40 -05:00
Sarah Chavis
495d617b01
draft release notes and explicit anchors for easier linking (#27431) 2024-06-11 13:29:55 -07:00
Scott Miller
e315ef31ec
Remove the Beta flag from Seal HA (#27437) 2024-06-11 16:36:58 +01:00
Peter Wilson
3f11c24c13
VAULT-23335: Audit - Exclusion Docs (Draft) (#26696)
* Added exclusion draft docs

* added message to link exported types RequestEntry and ResponseEntry to website docs

* Update website/content/docs/enterprise/audit/exclusion.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/enterprise/audit/exclusion.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/enterprise/audit/exclusion.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/enterprise/audit/exclusion.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/enterprise/audit/exclusion.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/enterprise/audit/exclusion.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/enterprise/audit/exclusion.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/enterprise/audit/exclusion.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/enterprise/audit/exclusion.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/enterprise/audit/exclusion.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/enterprise/audit/exclusion.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/enterprise/audit/exclusion.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/enterprise/audit/exclusion.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* `an` => `a`

* quotes

* Update website/content/docs/enterprise/audit/exclusion.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/enterprise/audit/exclusion.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/enterprise/audit/exclusion.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/partials/audit-options-common.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* JSON {} 'objects'

* condition is optional

* Update website/content/docs/enterprise/audit/exclusion.mdx

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-06-11 08:39:54 +01:00
divyaac
ca9c4df71e
Deprecates current_billing_period (#27426)
* Applied oss patches

* Added changelog

* Edited upgrade guide
2024-06-10 14:33:38 -07:00
Scott Miller
de84d373c1
Document environment variable usage in Seal HA (#27421)
* Document how environment variables work with seal names

* wording
2024-06-10 11:37:59 -05:00
Mary Frances
0ca6fe9af2
Update mongodbatlas.mdx (#27395)
Capitalize Atlas and add space in note.
2024-06-10 10:44:03 -04:00
divyaac
59320bb60b
Deprecated default_report_months (#27350)
* Deprecated default_report_months through docs and upgrade guides

* Added upgraade doc

* Update website/content/docs/upgrading/upgrade-to-1.18.x.mdx

Co-authored-by: Mike Palmiotto <mike.palmiotto@hashicorp.com>

* Update website/content/api-docs/system/internal-counters.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/upgrading/upgrade-to-1.18.x.mdx

Co-authored-by: Mike Palmiotto <mike.palmiotto@hashicorp.com>

* Update vault/logical_system_activity.go

Co-authored-by: Mike Palmiotto <mike.palmiotto@hashicorp.com>

* updated code sample

* Added changelog

* Update website/content/docs/upgrading/upgrade-to-1.18.x.mdx

Co-authored-by: Mike Palmiotto <mike.palmiotto@hashicorp.com>

* Update changelog/27350.txt

Co-authored-by: Mike Palmiotto <mike.palmiotto@hashicorp.com>

* Update website/content/docs/upgrading/index.mdx

Co-authored-by: Mike Palmiotto <mike.palmiotto@hashicorp.com>

* Update upgrade-to-1.18.x.mdx

* Update upgrade-to-1.18.x.mdx

* Added docs nav

* Edited docs nav

* Edited docs

---------

Co-authored-by: Mike Palmiotto <mike.palmiotto@hashicorp.com>
Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-06-06 21:58:54 +00:00
Jonathan Frappier
ef10c1a2a4
Add TCP TLS guide (#27318)
* Add TCP TLS guide

* Fix example listener stanza missing }

* Update website/content/docs/configuration/listener/tcp-tls.mdx

Co-authored-by: Jamie Finnigan <jfinnigan@hashicorp.com>

* Update website/content/docs/configuration/listener/tcp-tls.mdx

Co-authored-by: Jamie Finnigan <jfinnigan@hashicorp.com>

* Update website/content/docs/configuration/listener/tcp-tls.mdx

Co-authored-by: Jamie Finnigan <jfinnigan@hashicorp.com>

* Update website/content/docs/configuration/listener/tcp-tls.mdx

Co-authored-by: Jamie Finnigan <jfinnigan@hashicorp.com>

* Update website/content/docs/configuration/listener/tcp-tls.mdx

Co-authored-by: Jamie Finnigan <jfinnigan@hashicorp.com>

* Update website/content/docs/configuration/listener/tcp-tls.mdx

Co-authored-by: Jamie Finnigan <jfinnigan@hashicorp.com>

* Suggestions for TCP-TLS docs (#27335)

* recreating edits

* Fix nav entry

---------

Co-authored-by: Jamie Finnigan <jfinnigan@hashicorp.com>
Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-06-05 09:48:10 -04:00
John-Michael Faircloth
b9a2f83019
docs: note vle is not supported with aws snapstart (#27329)
* docs: note vle is not supported with aws snapstart

* Update website/content/docs/platform/aws/lambda-extension.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-06-04 21:31:49 -07:00
vinay-gopalan
5acc4331ea
Add WIF documentation for Azure Auth and Secrets engines (#27185) 2024-06-03 13:17:13 -07:00
vinay-gopalan
01ccf580d8
Add WIF documentation for GCP Auth and Secrets engines (#27170)
Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-06-03 13:16:56 -07:00
Violet Hynes
1d87ed8aaf
Add docs and changelog for PR 9733 (#27313) 2024-06-03 14:09:57 -04:00
Violet Hynes
92e995c68e
Note that Vault Proxy is supported as a Windows Service (#27306)
* Note that Vault Proxy is supported as a Windows Service

* Formatting
2024-05-31 13:04:17 -04:00
JMGoldsmith
896e825549
known issue with autopilot upgrades (#27286)
* known issue with autopilot upgrades

* Update releases

* Fix typo

* Fix typo

Co-authored-by: Ellie <ellie.sterner@hashicorp.com>

* Update 1.15.0.mdx

* Update 1.16.1.mdx

---------

Co-authored-by: Ellie <ellie.sterner@hashicorp.com>
Co-authored-by: Tony Wittinger <anwittin@users.noreply.github.com>
Co-authored-by: davidadeleon <56207066+davidadeleon@users.noreply.github.com>
2024-05-31 12:39:34 -04:00
Ben Ash
5672937149
Update docs for VSO v0.7.1 (#27296) 2024-05-30 18:56:30 -04:00
Jonathan Frappier
92a4fde589
Add note about HVS secret sync (#27285)
* Add note about HVS secret sync

* Update website/content/docs/sync/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-05-30 16:21:51 -04:00
Seena Fallah
5c275e7d88
agent: allow changing file ownership in file sink (#27123)
* agent: allow changing file ownership in file sink

Allow changing the ownership of the token file in file sink.

Signed-off-by: Seena Fallah <seenafallah@gmail.com>

* Consistency: id -> ID

* Add changelog

* Remove empty line in changelog

* agent: add godoc for TestFileSinkMode_Ownership

Signed-off-by: Seena Fallah <seenafallah@gmail.com>

---------

Signed-off-by: Seena Fallah <seenafallah@gmail.com>
Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>
2024-05-30 15:11:37 -04:00
jeremyaranas-hashicorp
b8d482c2fa
Updated Sentinel replication namespace (#27214)
Co-authored-by: Jonathan Frappier <92055993+jonathanfrappier@users.noreply.github.com>
2024-05-30 12:03:16 -04:00
Lucy Davinhart || Strawb System
b5e58a73b0
Update raft.mdx (#27275) 2024-05-30 10:33:56 -04:00
Brian Shumate
39a0dea8ad
Docs: Add recommended patterns (#27257)
* Docs: Add recommended patterns

- Create security folder
- Move security model to security folder as index page
- Add recommended patterns page to security folder
- Update navigation

* Add diagram content

* Rework navigation placement
2024-05-29 11:06:16 -04:00
markafarrell
476b0d57c9
Add vault.agent.authenticated metric (#26570)
* add vault.agent.authenticated metric

fix metric name

* Update command/agentproxyshared/auth/auth.go

---------

Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>
2024-05-28 12:28:24 -04:00
Ben Ash
990a25aee2
Update docs for VSO v0.7.0 (#27245) 2024-05-27 19:52:55 -04:00
Roberto Hidalgo
6e72397a86
Allow setting of Consul ServiceMeta tags from config file (#11084)
* Allow setting of Consul ServiceMeta tags from config file

probably a bad idea, let's see how it works
scaffold tests

* kick circleci

* Add links to consul docs

Co-authored-by: Violet Hynes <a.xenasis@gmail.com>

* add changelog note

* use relative developer docs links

* address feedback

* please linter

---------

Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>
2024-05-27 16:28:10 -04:00
Luis (LT) Carbonell
8298e79e45
Add replication heartbeat metric docs (#27229) 2024-05-24 14:51:29 -04:00
Sarah Chavis
53ec4d5f7b
[DOCS] Manage resources with TF (#27171)
---------

Co-authored-by: CJ <105300705+cjobermaier@users.noreply.github.com>
Co-authored-by: Brian Shumate <brianshumate@users.noreply.github.com>
2024-05-24 09:55:27 -07:00
John-Michael Faircloth
f528036e45
docs: ldap secrets hierarchical paths (#27203)
* docs: ldap secrets hierarchical paths

* changelog

* Apply suggestions from code review

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* role_name => set_name

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-05-24 09:10:59 -05:00
Ellie
7438d63f81
docs: document known issue sending sighup to ent standby node (#27155)
* docs: document known issue sending sighup to ent standby node

* be more specific with cause of panic

* add partial to upgrade guides for 1.14, 1.15, 1.16
2024-05-24 06:38:07 -05:00
miagilepner
d5e7ac934a
VAULT-24580: Add ACME to client count docs (#27040)
* add acme client documentation

* add to all metrics

* add acme to current month response
2024-05-24 11:30:32 +02:00
Milena Zlaticanin
309d832462
Add AWS Auth WIF docs (#27054)
* add aws auth wif docs

* update docs

* update docs
2024-05-23 12:58:08 -07:00
Adam Rowan
3d5a372ce3
Update interoperability-matrix.mdx (#27195)
Updating to include a new Rubrik KMIP integration with Vault.
2024-05-23 09:41:23 -07:00
Steven Clark
0bb3ddf7a7
Update cert metadata docs (#27025)
* Update cert metadata docs

 - Add missing enterprise notices on parameters and titles
 - Mention that the metadata parameter is a base64 encoded string
 - Tweak the no_store_metadata description
 - Update some entries within the PKI considerations page

* Add serial_number to read certificate metadata sample response

* Update fields sign-verbatim is affected by the specified role
2024-05-16 11:08:31 -04:00
Yoko Hyakuna
f12c5238db
[Docs] Point to the pricing page rather than the product page (#27026)
* Point to the pricing page rather than the product page

* Empty-Commit

* Add 'appropriate' to the license statement

* Use the partial to mention about VE license

* Minor fix

* add newline

* Revert "add newline"

This reverts commit 64615cba08.

---------

Co-authored-by: Nels Andereck <nels.andereck@hashicorp.com>
2024-05-15 17:49:01 -07:00
Mike Palmiotto
ecd164386c
Add a known issue for perf standby reverting to standby (#27062) 2024-05-15 17:49:40 -04:00
Jonathan Frappier
7bdc7c64bf
Fix broken MFA links, add links to bottom of page (#27061) 2024-05-15 17:24:47 -04:00
Sarah Chavis
8d2362364f
[DOCS] Correct code block language (#26996) 2024-05-13 16:39:20 -04:00
CJ
01c95e04ec
fix url to anti patterns (#26975) 2024-05-13 09:16:40 -07:00
CJ
5787c17b97
Docs/waf vault tf (#26515)
---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
Co-authored-by: Chris Stella <chris.stella.84@gmail.com>
2024-05-13 08:21:06 -07:00
Sarah Chavis
b38fdef012
Add reading guide for designing Vault clusters (#26947) 2024-05-10 17:41:32 -07:00
Daniel Greeninger
c87f1b90b5
Update limits.mdx (#26704)
corrected typo
2024-05-10 17:35:33 -07:00
Meggie
a5c9364c68
Added some notes about TLS and browser Secure Contexts (#26946)
* Added some notes about TLS and browser Secure Contexts

* Fixed an unrelated indent and color for note

* Bolding word to add visual distinction
2024-05-10 16:01:54 -04:00
Paul Banks
0a06215d1a
Documentation for Adaptive Overload Protection (#26690)
* Document enabling config

* Fix nav data JSON after disabling over-zealous prettifier

* Address review feedback

* Add warning about reloading config during overload

* Bad metrics links

* Another bad link

* Add upgrade note about deprecation

---------

Co-authored-by: Mike Palmiotto <mike.palmiotto@hashicorp.com>
2024-05-10 17:55:57 +01:00
Adam Rowan
6f946bc2af
Update interoperability-matrix.mdx (#26889)
Updating the Interoperability Matrix to account for new Vault KMIP and transit integrations
2024-05-09 11:20:49 -07:00
Peter Wilson
8778240665
VAULT-26466: audit - docs for including correlation ID headers by default (#26778)
* Docs for correlation ID changes

* Updates

* Update website/content/docs/audit/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/audit/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/audit/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/audit/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Create upgrade 1.17 doc and add audit headers info

* Update website/content/docs/audit/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/audit/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/audit/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/upgrading/upgrade-to-1.17.x.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-05-09 17:58:01 +00:00
Steven Clark
0637f5e316
PKI: Change sign-intermediate to truncate notAfter by default (behavior change) (#26796)
* PKI: Change sign-intermediate to truncate notAfter by default

 - The PKI sign-intermediate API allowed an end-user to request a TTL
   value that would extend beyond the signing issuer's notAfter. This would
   generate an invalid CA chain when properly validated.
 - We are now changing the default behavior to truncate the returned certificate
   to the signing issuer's notAfter.
 - End-users can get the old behavior by configuring the signing issuer's
   leaf_not_after_behavior field to permit, and call sign-intermediary
   with the new argument enforce_leaf_not_after_behavior to true. The
   new argument could also be used to enforce an error instead of truncating
   behavior if the signing issuer's leaf_not_after_behavior is set to err.

* Add cl

* Add cl and upgrade note

* Apply suggestions from code review

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-05-09 11:22:04 -04:00
Ellie
84d734d673
[docs] document known issue for azure secrets engine failing on role creation (#26881)
* document known issue for azure secrets engine failing on role creation

* fix empty space

* remove new line

* add workaround

* remove space

---------

Co-authored-by: Tony Wittinger <anwittin@users.noreply.github.com>
2024-05-09 09:48:22 -05:00
Steven Clark
fe2b4c6f7a
PKI: Allow operators to increase the maximum TTL for ACME issued certificates (#26797)
* PKI: Allow operators to increase the maximum TTL for ACME issued certificates

* Add cl
2024-05-09 10:41:28 -04:00
Steven Clark
259cfbf618
Add missing delegated_auth_accessors config field to /sys/mounts/<path> response (#26876)
* Add missing delegated_auth_accessors config field to /sys/mounts/<path> response

 - The field hadn't been properly populated in the JSON struct being returned
   through the API response, but had been properly set in the stored structs
   in the backend.
 - Add missing update to the command tune docs for the -delegated-auth-accessors
   option that existed
 - Add -delegated-auth-accessors to the secret enable vault command along with
   a docs update

* Add cl

* Fix documentation, using a comma separated list does not work

* Apply suggestions from code review

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Drop plural on doc update

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-05-08 19:58:46 +00:00
Peter Wilson
e9e79b4c16
Tweak text to clarify (#26804) 2024-05-07 11:42:07 +01:00
Meggie
f298ef763a
Fix docker image in developer quickstart (#26805)
We were pointing to the deprecated official images (https://hub.docker.com/_/vault) instead of the verified publisher images (https://hub.docker.com/r/hashicorp/vault) which is the one we publish `latest` to.

See also https://github.com/hashicorp/vault/pull/23581
2024-05-06 11:22:25 -04:00
benz0
758c967369
Update tcp.mdx (#26816)
per customer request in support ticket #141025 I've updated the description of tls_disable_client_certs to provide clarification.

previous pr for this change was approved but needed to be resubmitted because of problems with my GH account.  See #26601
2024-05-06 11:03:13 -04:00
Robert
1bfc4f90eb
Adjust sync clients reference link (#26818) 2024-05-03 15:37:55 -05:00
Violet Hynes
f2b4ca4def
VAULT-24736 CE changes for static secret capability behaviour toggle (#26744) 2024-05-03 14:12:19 -04:00
gabeknell
de11f27713
Update kmip.mdx (#24159)
* Update kmip.mdx

Added "performance standby" to the servers the KMIP client can connect to

---------

Co-authored-by: Peter Wilson <peter.wilson@hashicorp.com>
2024-05-02 16:01:58 +00:00
prabhat-hashi
c88967abb5
Docs- Update info on key rotation (#23274)
* Docs- Update info on key rotation

Added a sentence about needing to seal-rewrap if you want to disable or delete old key.

* rectified the url for seal-rewrap

rectified the url for seal-rewrap

* fixed some grammar

* Update website/content/docs/configuration/seal/pkcs11.mdx

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-05-01 15:42:54 -07:00
Mitch Pronschinske
07bfa6bd92
Fix "auto unseal" case inconsistency (#25119)
There was inconsistency in the capitalization of auto unseal in this doc.  The initial heading had it right. It shouldn't be capitalized according to the documentation style guidance for feature capitalization. Also, high availability doesn't need to be capitalized.

Change warning to tag syntax so it's clear what should be part of the aside

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-05-01 15:32:34 -07:00
prabhat-hashi
02a8900f7b
Docs - Updated info on seal-rewrap during seal migration (#23275)
Added a note about seal-rewrap in the steps to perform seal migration post Vault 1.5.1
---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-05-01 15:18:39 -07:00
Lucy Davinhart || Strawb System
674edc5bc6
Link to deprecation notice page in upgrade guide (#23569)
* Link to deprecation notice page in upgrade guide

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-05-01 15:17:46 -07:00
Soromeister
fbdc1e6248
Add link for Priority matching in Policies. (#24341)
Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-05-01 15:16:45 -07:00
kevin-loehfelm
1b21400195
added documentation for mongodb atlas database secrets engine eventua… (#24152)
* added documentation for mongodb atlas database secrets engine eventual consistency
2024-05-01 14:19:26 -07:00
Jason Peng
e17b57f5c1
Update vault-ha-upgrade.mdx to not step-down during upgrades (#24457)
Due to the reported issue under https://github.com/hashicorp/vault/pull/24441, we identified that there are users issuing step-down during the upgrade, which is unintended.

We modified the documentation to make it clear that step-down should not be attempted, in addition rephrased the sentence with "step-down" word and exclude that term to avoid confusion.
2024-05-01 14:18:07 -07:00
preetibhat6
6573fdb6c2
Update events.mdx (#25835)
Added missing ' to the command at the end
2024-05-01 14:12:59 -07:00
sylvia-petsanova
716d577190
Add policy creation to AppRole setup (#26700)
It's not immediately obvious that the demo policy needs to be created beforehand and does not exist if only the tutorial steps are followed. Prompted by support ticket ZD-143426.
2024-05-01 14:09:02 -07:00
thegatsbylofiexperience
5b845c83ff
Add canonicalArn as a entity alias name (#22460)
* Add canonicalArn as a entity alias name
* Add Canonical Arn to iam_alias documentation
2024-04-29 15:56:26 -04:00
divyaac
4bbd44a0f6
Added docs for the error message changes (#26687)
* Added docs for the errror message changes

* Edit verbage

* Update website/content/docs/concepts/tokens.mdx

Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>

* Update website/content/docs/concepts/tokens.mdx

Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>

* Update website/content/docs/concepts/tokens.mdx

Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>

---------

Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>
2024-04-29 12:34:08 -07:00
Robert
6ccb2bd64a
Add new field to docs, fix changed names in example hcl (#26669) 2024-04-26 15:24:40 -05:00
Robert
5319d35ec8
Add access management section to azure kv (#26668) 2024-04-26 15:24:30 -05:00
Rachel Culpepper
b49622076f
Add docs for cmac (#26654)
* add docs for cmac

* move cmac
2024-04-25 17:05:11 -05:00
Robert
20647788bf
Add activation section to the sync overview page (#26627)
* Add activation section to sync overview

* Better formatting

* Match hcp-docs format
2024-04-25 16:59:23 -05:00
John-Michael Faircloth
496912e041
docs: update release notes for ldap auth change (#26632) 2024-04-25 08:40:19 -07:00
Sarah Chavis
ea365ef804
[DOCS] Fix status placeholder (#26640) 2024-04-24 18:33:16 -07:00
Ben Ash
15bdb500b9
Update docs for VSO v0.6.0 (#26635) 2024-04-24 16:47:37 -04:00
Sarah Chavis
e12d5f0d8e
[DOCS] Add missing commits (#26625)
* Initial drafting and deprecation info cleanup
* Adding more notes about deprecations and plans. (#26618)
* move deprecation notice to a partial for reuse elsewhere
* Add redirect for deleted FAQ

---------

Co-authored-by: Meggie <meggie@hashicorp.com>
2024-04-24 13:04:30 -04:00
Sarah Chavis
643028f931
[DOCS] Update deprecation pages (#26597)
Co-authored-by: Meggie <meggie@hashicorp.com>
2024-04-24 09:28:49 -07:00
CJ
b2580d4212
Add missing integrated storage reference architecture diagram (#26600)
* add missing diagram

* fix path to file

---------

Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>
2024-04-23 12:07:18 -07:00
John-Michael Faircloth
d11819316b
docs: remove non-existing file reference (#26602) 2024-04-23 11:38:41 -07:00
Yoko Hyakuna
2becdceab0
Replace 'HCP Vault' with 'HCP Vault Dedicated' (#26457)
* Replace 'HCP Vault' with 'HCP Vault Dedicated'

* Replace 'HCP Vault' with 'HCP Vault Dedicated' where applicable

* Replace 'Terraform Cloud' with 'HCP Terraform'

* Minor format fixes

* Update the side-nav title to 'HCP Terraform'

* Undo changes to Terraform Cloud secrets engine
2024-04-22 08:44:13 -04:00
akshya96
d44ec076b8
retention months docs changes (#26563) 2024-04-19 14:57:10 -07:00
John-Michael Faircloth
76d33bfce7
docs: update 1.16 upgrade guide for ldap auth entity alias change (#26557) 2024-04-19 13:53:20 -04:00
JMGoldsmith
7b4f6409c6
[DOCS] Updating approle docs and token partial to include batch token prefer… (#26490)
* updating approle docs and token partial to include batch token preference

* Update website/content/docs/auth/approle.mdx

Co-authored-by: Brian Shumate <brianshumate@users.noreply.github.com>

* Update website/content/partials/tokenstorefields.mdx

Co-authored-by: Brian Shumate <brianshumate@users.noreply.github.com>

* Update website/content/docs/auth/approle.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

---------

Co-authored-by: Brian Shumate <brianshumate@users.noreply.github.com>
Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-04-19 12:32:12 -04:00
CJ
66212d1444
fix key metrics title (#26539) 2024-04-19 11:33:24 -04:00
Sarah Chavis
79d9bf1572
[DOCS] Update LTS overview (#26483)
Add image and tighten language around LTS maintenance vs standard maintenance
Replace "support" with "maintenance" in the image alt text
Apply feedback
2024-04-18 13:54:30 -04:00
Brian Shumate
5aaa489f80
Docs: migrate key metrics from WAF to telemetry (#26499)
- Add key metrics document to telemetry internals documentation
2024-04-18 11:45:37 -04:00
Nick Cabatoff
89deeab507
Document replication canary and clock skew. (#25763) 2024-04-16 10:49:05 -04:00
Theron Voran
69fb6c77c9
docs/vault-agent-injector: cross namespace secret sharing example (#26386)
Adds an agent injector example showing annotations for cross namespace
secret sharing.

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-04-15 15:14:07 -07:00
Sarah Chavis
6c01838269
fix release notes (#26404) 2024-04-15 12:06:35 -07:00
JJ
37c5982761
Editorial changes to integrated-storage.mdx (#26416)
Approximately half a dozen fixes to spelling and grammar.

Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>
2024-04-15 11:51:11 -07:00
Chris Capurso
e1c3f4ac17
clarfiy login MFA not supported for token auth (#26411) 2024-04-15 11:09:59 -04:00
CJ
1362f92477
Move Protecting secrets with Vault transform secrets engine to Vault Transform (#26378)
* first commit to move article from waf to vault docs

* Apply suggestions from code review

Co-authored-by: Brian Shumate <brianshumate@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: Brian Shumate <brianshumate@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: Brian Shumate <brianshumate@users.noreply.github.com>

* Update transform.mdx

Updated the description and moved image.

* updated resources

* passive voice fix

* passive voice fix

* Apply suggestions from code review

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

---------

Co-authored-by: Brian Shumate <brianshumate@users.noreply.github.com>
Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-04-15 10:53:38 -04:00
soly-hashicorp
140b415e2c
Update 1.16.1.mdx (#26373)
Secret Syncing is no longer in Beta and is now GA in 1.16.1
2024-04-12 15:48:45 -07:00
Theron Voran
e4f9d024c8
docs/vault-helm: updates for v0.28.0 release (#26282) 2024-04-12 13:37:56 -07:00
Violet Hynes
eb35916034
Fix leased non-renewable secrets docs, and some capitalization (#26370)
* Fix leased non-renewable secrets docs, and some capitalization

* Update based on review

* typo
2024-04-12 15:56:33 -04:00
Michael Kosir
691bf9b3a7
Docs: update deprecated transform command (#26368)
* update deprecated command

* fixed spacing
2024-04-12 09:03:03 -04:00
Brian Shumate
ba6a9c2160
Docs: WAF: initial cloud access management content (#26321)
Co-authored-by: CJ <105300705+cjobermaier@users.noreply.github.com>
2024-04-10 12:11:28 -04:00
divyaac
1e3efed2fa
Documentation for Self Healing Auto Auth Proxy and Agent (#26324)
* Documentation for Self Healing Auto Auth Proxy and Agent'

* Added or

* Edited one more thing
2024-04-09 13:40:15 -07:00
Samuel Lee
31aaf4e50b
Update azurekeyvault.mdx (#26308)
Fixed typo in Azure Key Vault docs - mentions GCP Cloud KMS instead of Azure Key Vault KMS
2024-04-09 09:13:19 -04:00
Victor Rodriguez
02312cbb57
Fix typo in KMIP backend documentation. (#26304) 2024-04-08 16:08:41 -04:00
James Bayer
d1fda882a5
[DOCS] Update kmip.mdx to add Cert Authority details (#23907)
* Update kmip.mdx to add Cert Authority details

* Update website/content/docs/secrets/kmip.mdx

Accepted suggestion

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-04-08 15:51:05 -04:00
Paul Banks
9c12a6acc7
Docs/mount namespace entry size (#26119)
* Update documentation for namespace/mount entry size limit

* Clarify defaults

* Better wording for storage size partial that appears on different pages

* Active voice!

* No this

* Fix confusing terminology
2024-04-08 12:43:07 +01:00
Jason N
e9cb557ef1
Add support for forwarded Tls-Client-Cert (#17272)
* Add support for x_forwarded_for_client_cert_header

* add changelog entry

* add tests for a badly and properly formatted certs

* both conditions should be true

* handle case where r.TLS is nil

* prepend client_certs to PeerCertificates list

* Add support for x_forwarded_for_client_cert_header

* add changelog entry

* add tests for a badly and properly formatted certs

* both conditions should be true

* handle case where r.TLS is nil

* prepend client_certs to PeerCertificates list

* add option for decoders to handle different proxies

* Add support for x_forwarded_for_client_cert_header

* add changelog entry

* add tests for a badly and properly formatted certs

* both conditions should be true

* handle case where r.TLS is nil

* prepend client_certs to PeerCertificates list

* add option for decoders to handle different proxies

* fix tests

* fix typo

---------

Co-authored-by: Alexander Scheel <alex.scheel@hashicorp.com>
Co-authored-by: Scott Miller <smiller@hashicorp.com>
Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>
2024-04-05 11:22:46 -05:00
John-Michael Faircloth
c05e704f07
docs: add known issue for jwt auth config (#26276)
* docs: add known issue for jwt auth config

* Update website/content/partials/known-issues/1_16-jwt_auth_config.mdx

Co-authored-by: Heat Hamilton <55773810+heatlikeheatwave@users.noreply.github.com>

---------

Co-authored-by: Heat Hamilton <55773810+heatlikeheatwave@users.noreply.github.com>
2024-04-04 21:25:33 +00:00
Sarah Chavis
038aaa3ff7
1.16 release notes and beta cleanup (#26247)
Co-authored-by: Tom Proctor <tomhjp@users.noreply.github.com>
2024-04-03 22:18:40 +01:00
Sarah Chavis
262997a532
[DOCS] LTS overview (#25945)
Co-authored-by: Jared Kirschner <85913323+jkirschner-hashicorp@users.noreply.github.com>
2024-04-03 12:26:29 -07:00
Tom Proctor
dbe6e4ee2d
Docs: Fix SQL Server EKM Provider KEK rotation instructions (#25255) 2024-04-03 11:35:31 +01:00
Theron Voran
92c58476ee
docs/vault-secrets-operator: encrypted client cache storage (#25475)
Adding a howto guide for enabling the encrypted Vault client cache
storage for helm and OperatorHub installs. Add more detail about
client caching to the main Vault source page, with a link to the
guide.

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-04-01 14:45:13 -07:00
VAL
8e19b7b19b
Clarify DR perf-standby behavior (#26230) 2024-04-01 10:38:00 -07:00
Thy Ton
df477f6404
docs make kubernetes_ca_cert optional on kubernetes auth (#25963)
---------

Co-authored-by: Ben Ash <32777270+benashz@users.noreply.github.com>
Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-03-27 15:45:43 -07:00
John-Michael Faircloth
e019b62dd6
docs: add ldap auth login known issue (#26179)
* docs: add ldap auth login known issue

* add anon group search issue
2024-03-27 16:14:44 -05:00
Scott Miller
f319d98665
Re-add beta designation (#26190)
* Re-add beta designation

* nl

* mark the migration section beta too

* beta
2024-03-27 15:16:27 -04:00
NikolaiMagicnet
c9dafc1971
Fixed the URL (#26178)
Co-authored-by: Chris Capurso <1036769+ccapurso@users.noreply.github.com>
2024-03-27 12:10:19 -04:00
Robert
5fac327dae
Secrets Import documentation (#25594)
* Start import docs

* Use hideClipboard block on output

* Reorganize mappings and source docs

* Change experimental to alpha

* Change list tag to alpha

* Apply suggestions from code review

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-03-27 09:35:29 -05:00
Peter Wilson
7bd75eb858
Known issues: Vault Enterprise - Performance Standby nodes audit log all request headers (#26158)
* Add known issue docs for Ent Perf Standby audit header logging issue

* attempt to improve description
2024-03-26 14:54:11 +00:00
Robert
483dd209f6
Overwrite restrictions documentation for GCP (#25645)
* Move secret write access conditions info to each destination page, reword index to match

* Add condition info for GCP

* Remove unrelated note copied from AWS

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Link to individual access control sections, rename section titles, make tip more specific

* Add image showing where to add IAM Conditions

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-03-25 18:51:12 -05:00
Josh Black
6d69761751
raft-wal docs (#25572)
* starting on docs

* add docs for raft-wal

* some tweaks

* Apply suggestions from code review

Co-authored-by: Mike Palmiotto <mike.palmiotto@hashicorp.com>

* Edits for Raft WAL (#26123)

* not just one filename

* update file pattern for wal files

---------

Co-authored-by: Mike Palmiotto <mike.palmiotto@hashicorp.com>
Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-03-25 16:42:48 -07:00
aphorise
7bb5561b58
Docs: Policy Syntax page to include UI details. (#25449)
Co-authored-by: Jason O'Donnell <2160810+jasonodonnell@users.noreply.github.com>
Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-03-25 22:45:01 +00:00
Christopher Swenson
74c350474b
docs: Adding events to a plugin (#26083)
This adds a short doc describing the basic process
of adding event notifications to a plugin as well
as some examples and best practices.

Co-authored-by: John-Michael Faircloth <fairclothjm@users.noreply.github.com>
2024-03-25 16:50:49 +00:00
Yoko Hyakuna
de7c905477
[Docs] Remove 'Beta' badge for Secrets Sync (#26116)
* Remove the beta badge

* Remove the 'beta' badge & callout
2024-03-22 15:03:27 -07:00
Sarah Chavis
f661f4354c
Add UI policy notes partial and include in overview (#25956) 2024-03-22 14:24:12 -07:00
Max Coulombe
fa469f8bdc
- removed beta badges (#26120) 2024-03-22 17:00:30 -04:00
Karuppiah Natarajan
30667916b7
fix link to specifying ttl and audience section of kubernetes oidc provider (#26097) 2024-03-22 12:21:17 -04:00
Scott Miller
c6da02962d
Add a configuration flag for enabling multiseal (Seal HA), CE side (#25908)
* Add a configuration flag for enabling multiseal (Seal HA), CE side

* imports

* no quotes

* get rid of dep on ent config

* Abstract enableMultiSeal for a build time switch

* license headers

* wip

* gate physical seal gen fetch by a param

* docs tweak, remove core flag

* updates from the ent pr

* update stub

* update test fixtures for enable_multiseal

* use accessor

* add a test fixture for non-multiseal diagnose

* remove debugging crtuch

* Do handle phys seal gen info even if multiseal is off, in order to facilitate enable/disable safeties

* more enabled flag handling

* Accept seal gen info if we were previously disabled, and persist it

* update unit test

* Validation happens postUnseal, so this test is invalid

* Dont continue setting conf if seal loading fails during SIGHUP

* Update website/content/docs/configuration/seal/seal-ha.mdx

Thanks, that does sound much clearer

Co-authored-by: Jason O'Donnell <2160810+jasonodonnell@users.noreply.github.com>

* use validation if previous gen was enabled

* unit test update

* stub SetMultisealEnabled

* bring over more changes from ent

* this was an unfix

---------

Co-authored-by: Jason O'Donnell <2160810+jasonodonnell@users.noreply.github.com>
2024-03-22 14:23:05 +00:00
Scott Miller
14816dcf86
Be explicit about Shamir seals in Seal HA (#26092) 2024-03-22 09:25:20 -04:00
Ciara Clements
89c9f86f22
Update upgrade-to-1.13.x.mdx (#25990)
Changed the wording of "For integrated storage users, Vault needs to be upgraded to 1.13 will enable this feature by default." to be more clear and concise to "For integrated storage users, upgrading Vault to 1.13 will enable this feature by default."
2024-03-20 08:17:00 -07:00
mickael-hc
55b4f1c42f
docs: secrets-sync - move destination note (#26044) 2024-03-20 10:54:43 -04:00
Wes Gilleland
3106f26474
Fix small typo in troubleshooting-acme.mdx (#24547)
* Fix small typo in troubleshooting-acme.mdx

* Create changelog/24547.txt

* Delete changelog/24547.txt

---------

Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>
2024-03-20 09:16:19 -04:00
Jens Hofmann
846476e857
change shell command for userpass authentication (#24342)
Use vault auth enable instead of vault write, because I think it is more appropriate or the "new way"

Co-authored-by: Marc Boudreau <marc.boudreau@hashicorp.com>
2024-03-19 10:23:00 -04:00
jmarcelletti
79f0ce2d74
Update step-down.mdx (#19329)
Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>
Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-03-14 11:21:46 -07:00
Tom Proctor
6482672d12
Docs: Updated plugin versioning usage docs for pinned versions (#25607) 2024-03-14 17:29:21 +00:00
Ben Ash
77e3ebbad5
Update docs for VSO v0.5.2 (#25939) 2024-03-13 17:49:33 -04:00
Peter Wilson
187adf145d
Patch 2 (#25925)
* Update index.mdx

The link (https://developer.hashicorp.com/vault/docs/proxy/index) in this page https://developer.hashicorp.com/vault/docs/deprecation does not point anywhere

* Use relative link

Co-authored-by: Tom Proctor <tomhjp@users.noreply.github.com>

---------

Co-authored-by: Jose Merchan <jose.merchan@hashicorp.com>
Co-authored-by: Violet Hynes <a.xenasis@gmail.com>
Co-authored-by: Tom Proctor <tomhjp@users.noreply.github.com>
2024-03-13 11:30:26 -07:00
JJ
56e344b26a
Editorial changes to control-groups.mdx (#25582)
Some small corrections of punctuation and grammar.
2024-03-13 18:19:34 +00:00
Peter Wilson
61a5d449b0
updated docs (#25891) 2024-03-13 11:17:04 -07:00
Thomas Decaux
29dec5dfc4
fix azuread doc user_claim must be sub (#25896)
Fix error "claim "email" not found in token"

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-03-13 18:09:54 +00:00
MahmoudMansourr
56dcff5ea7
Update gcpkms.mdx "Added a new role required for key Import" (#25437)
the "cloudkms.importJobs.useToImport" role is missing from the documentation, however it's needed to distribute the keys to GCP'S KMS.
2024-03-13 18:02:58 +00:00
Pascal Reeb
646034a97d
fix(oidc/azuread): set correct oidc_scopes (#25477)
Co-authored-by: Peter Wilson <peter.wilson@hashicorp.com>
2024-03-13 18:00:22 +00:00
Phil Jay
a4040515b8
Update the AD to LDAP migration guide with a note about lazy vs automatic password rotation (#25374)
* Update migration-guide.mdx

Add a note about lazy vs automatic

* Apply suggestions from code review

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Provide example in note

Thought it might be useful to have an example of when the difference in behaviour is an issue

* Update website/content/docs/secrets/ad/migration-guide.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-03-13 17:59:51 +00:00
danielmenezesbr
54241e2932
Updated the GRANT statement to use gv_$session instead of gv$session (#25861)
Co-authored-by: Peter Wilson <peter.wilson@hashicorp.com>
2024-03-13 17:57:08 +00:00
Peter Wilson
a311735761
Support pre-hashed passwords with userpass backend (#25862)
* allows use of pre-hashed passwords with userpass backend

* Remove unneeded error

* Single error check after switch

* use param name quoted in error message

* updated test for quoted param in error

* white space fixes for markdown doc

* More whitespace fixes

* added changelog

* Password/pre-hashed password are only required on 'create' operation

* docs indentation

* Update website/content/docs/auth/userpass.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Updated docs

* Check length of hash too

* Update builtin/credential/userpass/path_user_password_test.go

:)

Co-authored-by: Kuba Wieczorek <kuba.wieczorek@hashicorp.com>

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
Co-authored-by: Kuba Wieczorek <kuba.wieczorek@hashicorp.com>
2024-03-12 18:16:11 +00:00
miagilepner
e31413d6cf
VAULT-23089: Doc updates for secret sync billing (#24955)
* add secret sync clients

* update docs and add metrics

* add to operator usage

* entities -> secrets
2024-03-12 10:06:51 +00:00
Theron Voran
c0cef5d807
docs/vault-k8s injector: update for v1.4.0 release (#25790)
Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-03-07 22:03:31 -08:00
Austin Gebauer
57f7fa9c60
docs: adds enterprise documentation for plugin wif (#25706)
* docs: adds enterprise documentation for plugin wif

* attempt fix anchor link

* Update website/content/api-docs/secret/identity/tokens.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/secrets/aws.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/secrets/aws.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/secrets/aws.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/secrets/aws.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/secrets/aws.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/secrets/aws.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/api-docs/secret/identity/tokens.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/api-docs/secret/identity/tokens.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/secrets/aws.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* remove API section for plugin WIF

* commas

* move wif out of subsection

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-03-07 19:14:30 -08:00
Steven Clark
43f8c7a6f0
PKI EST docs (#25521)
* PKI EST docs

 Initial draft of the PKI EST setup and API docs for feedback

* Add missing enable_sentinel_parsing param to API docs

* Update grammar

* Some API doc feedback

* Note about dedicated auth mounts

* Additional PR feedback

---------

Co-authored-by: Scott G. Miller <smiller@hashicorp.com>
2024-03-07 14:27:59 -05:00
Peter Wilson
d94418c3e5
VAULT-24450: Make Audit Filtering 'Enterprise Only' in documentation (#25814)
* Move audit filtering to enterprise

* Update to use Enterprise tag

* Update Ent only at top of page to use partial
2024-03-07 17:34:36 +00:00
Victor Rodriguez
e4aba1516d
Do not refresh seal-wrapped values when there are unhealthy seals. (#25801)
* Do not refresh seal-wrapped values when there are unhealthy seals.

Modify Access.IsUpToDate() to consider entries as being up-to-date when one or
more encryption wrappers fail to encrypt the test value, since re-wrapping the
value would result in the loss of the ciphertext for the unhealthy wrappers.

In addition, make Access.IsUpToDate() return true is the key set ID has not been
populated and the caller has not forced key ID refresh.

Make Access.Encrypt() return an error for any encryption wrapper that is skipped
due to being unhealthy.

* Update Seal HA documentation.

Mention that the barrier key and the recovery keys cannot be rotated while there
are unhealthy seals.

Document environment variable VAULT_SEAL_REWRAP_SAFETY.
2024-03-07 15:50:36 +00:00
Sarah Chavis
79227d0e06
[DOCS] Edits to audit filtering overview (#25676)
Edits to audit filtering overview
---------

Co-authored-by: Peter Wilson <peter.wilson@hashicorp.com>
2024-03-07 09:21:24 +00:00
Theron Voran
96b427f5b2
docs/vault-secrets-operator: supported openshift versions and OperatorHub options (#25682)
Also describes how to customize an operator install from OperatorHub

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-03-06 14:32:43 -08:00
Jamie Finnigan
18e7751b10
fix "Vault as a service" reference in namespace docs (#25749) 2024-03-06 13:35:46 -08:00
Peter Wilson
82e70616e1
Extra information about how to escape an @ as the first char in kv value (#25792)
* Extra information about how to escape an @ as the first char in kv value

* Update website/content/docs/commands/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-03-06 13:00:41 -08:00
Brian Shumate
823b7dab7a
Documentation: WAF: add merkle-check documentation (#25743)
* Documentation: WAF: add merkle-check documentation

- Update Enterprise / Replication navigation
- Move Replication page to Overview
- Add Check for Merkle tree corruption page

* Update website/content/docs/enterprise/replication/check-merkle-tree-corruption.mdx

Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>

* Update website/content/docs/enterprise/replication/check-merkle-tree-corruption.mdx

Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>

* Update website/content/docs/enterprise/replication/check-merkle-tree-corruption.mdx

Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>

* Update website/content/docs/enterprise/replication/check-merkle-tree-corruption.mdx

Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>

---------

Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>
Co-authored-by: CJ <105300705+cjobermaier@users.noreply.github.com>
2024-03-06 09:21:53 -05:00
Thy Ton
50aa6eea70
docs: add templated policies workflow example to kubernetes auth (#25694)
---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
Co-authored-by: Theron Voran <tvoran@users.noreply.github.com>
2024-03-01 15:11:14 -08:00
Steven Clark
09294e891a
Add notes around OCSP GET request issue (#25745)
* Add note around OCSP GET request issue

 - Fix some broken TOC links
 - Add a note in the api-docs and in the considerations page
   around Vault having issues with OCSP GET requests and that
   POST requests should be preferred.
 - Add existing known issue to all branches that are affected.

* Fix links to partial file for 1.12 and 1.13 upgrade docs
2024-03-01 15:25:07 -05:00
mickael-hc
8cbab3b09f
docs: update proxy auto-auth recommendations (#25746)
* update proxy auto-auth

recommmend 1 proxy per application when using auto-auth

* Update website/content/docs/agent-and-proxy/proxy/apiproxy.mdx

* Update website/content/docs/agent-and-proxy/proxy/apiproxy.mdx

* add feedback from @violethynes

cannot commit the suggestions due to them being marked as "outdated"
2024-03-01 12:18:36 -05:00
Scott Miller
7943a9e094
Add a fuller example of a Seal HA compatible seal stanza (#25704)
* Add a fuller example of a Seal HA compatible seal stanza

* abs link
2024-02-29 12:45:53 -06:00
Yoko Hyakuna
f7a00c7430
Add enterprise badge (#25707) 2024-02-29 08:41:24 -08:00
Milena Zlaticanin
3a844a2e45
Update Azure secrets docs + deprecation (#25637)
* Update Azure secrets docs + deprecation

* add changelog

* update

* update docs

* update deprec doc
2024-02-28 11:59:00 -07:00
Violet Hynes
5e42f9a8d3
VAULT-24385 docs updates for proxy static secret caching -> ent (#25677)
* VAULT-24385 docs updates for proxy static secret caching -> ent

* VAULT-24385 we -> you
2024-02-28 10:28:51 -05:00
Kianna
fc559052c7
UI: Addresses custom messages doc feedback from backport (#25683)
* Addresses feedback from backport

* Update website/content/docs/ui/custom-messages.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-02-27 14:53:33 -08:00
Mike Palmiotto
9ddd23cf62
Request Limiter docs (#25557)
Co-authored-by: miagilepner <mia.epner@hashicorp.com>
2024-02-27 16:24:44 -05:00
Kianna
f33cb01f78
Custom messages spelling and grammar fixes (#25668) 2024-02-27 11:34:13 -08:00
Scott Miller
da21b85133
Make encryption persistence timeout configurable via env var (#25636)
* Make the encryption tracking persistence timeout configurable via env

* docs

* changelog

* Update vault/barrier_aes_gcm.go

Co-authored-by: Steven Clark <steven.clark@hashicorp.com>

* use ParseDurationSecond

---------

Co-authored-by: Steven Clark <steven.clark@hashicorp.com>
2024-02-27 18:04:18 +00:00
Kianna
63de6e31a2
UI: Vault UI custom messages documentation (#25638)
* Move over custom messages documention to clean branch

* Update website/content/docs/ui/custom-messages.mdx

Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>

* Add ENTERPRISE badge

* Update website/content/docs/ui/custom-messages.mdx

Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>

* Update website/content/docs/ui/custom-messages.mdx

Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>

* Update website/content/docs/ui/custom-messages.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/ui/custom-messages.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/ui/custom-messages.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/ui/custom-messages.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/ui/custom-messages.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/ui/custom-messages.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/ui/custom-messages.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/ui/custom-messages.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/ui/custom-messages.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/ui/custom-messages.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/ui/custom-messages.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/ui/custom-messages.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update namespace alt text

---------

Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>
Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-02-26 22:13:16 +00:00
Peter Wilson
3aa5b915ee
VAULT-24362: Updated 'known issues' to include audit panic (#25632)
* Updated known issues for audit panic

* feedback
2024-02-26 22:06:29 +00:00
Violet Hynes
9ed834cdce
Fix a broken link (#25648) 2024-02-26 16:58:08 -05:00
Kevin Schoonover
19aeaa57a6
add support for 'LeaseRenewalThreshold' in vault agent (#25212)
* add support for 'LeaseRenewalThreshold' in vault agent

* allow LeaseRenewalThreshold to be nil

* address review comments

* Add changelog

---------

Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>
2024-02-26 15:49:31 -05:00
Christopher Swenson
ae9ec39d44
events: Now enterprise-only (#25640)
This removes the WebSockets endpoint for events
(which will be moved to the Enterprise repo) and
disables tests that rely on it unless they are
running in Enterprise.

It also updates documentation to document that
events are only available in Vault Enterprise.
2024-02-26 20:19:35 +00:00
Raymond Ho
2ab94c68ac
docs: github fingerprint (#25601) 2024-02-23 13:03:11 -08:00
Raymond Ho
006f52d4d6
docs: sync/reconciliation (#25576) 2024-02-22 23:12:02 +00:00
Raymond Ho
2b46f5e523
docs: sync/github-apps (#25569) 2024-02-22 22:53:15 +00:00
Mike Palmiotto
895ae9afc0
fix 1.16 upgrade guide (#25593) 2024-02-22 17:15:13 -05:00
Tom Proctor
34079f2c30
Docs: Plugin env priority updates for 1.16.0 (#25580) 2024-02-22 21:51:03 +00:00
Max Coulombe
ed9a4744d6
Added docs on how to grant & restrict access (#25584)
* + added docs on how to grant & restrict access

* Update website/content/docs/sync/index.mdx

* + added small precision on where Vault's responsibility ends

* Update website/content/docs/sync/index.mdx

Co-authored-by: Robert <17119716+robmonte@users.noreply.github.com>

---------

Co-authored-by: Robert <17119716+robmonte@users.noreply.github.com>
2024-02-22 16:29:26 -05:00
Mike Palmiotto
fac68810c1
Lease Count Quotas: include error message in docs (#25570)
Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-02-22 16:16:57 -05:00
Mike Palmiotto
8f9e884bee
Default Lease Count Quota: Document pre-1.9 upgrades (#25559) 2024-02-22 16:16:24 -05:00
Marc Boudreau
78c8340f77
Document known issue to release notes and upgrade guide for 1.16.0 (#25540)
* document known issue to release notes and upgrade guide for 1.16.0

* add link to new pages in docs-nav-data.json

* Update website/content/docs/release-notes/1.16.0.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/partials/known-issues/1_16-default-policy-needs-to-be-updated.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/partials/known-issues/1_16-default-policy-needs-to-be-updated.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/partials/known-issues/1_16-default-policy-needs-to-be-updated.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/partials/known-issues/1_16-default-policy-needs-to-be-updated.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/partials/known-issues/1_16-default-policy-needs-to-be-updated.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* use active voice

* changing the affected version

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-02-22 15:45:52 -05:00
Raymond Ho
ef4adca32c
add ldap credential rotation bug as known issue for 1.15.5 (#25535) 2024-02-21 12:54:26 -08:00
Max Coulombe
3b3dc14268
+ added sync telemetry doc (#25555) 2024-02-21 14:06:24 -05:00
Christopher Swenson
d3b853385d
Events: no longer in beta (#25562)
* Rename them to event notifications.
* Also remove reference to potentially allowing secrets in the future.
2024-02-21 11:02:16 -08:00
vinay-gopalan
2dc73f0636
Add documentation for AWS Plugin WIF (#25398) 2024-02-21 09:19:43 -08:00
miagilepner
5f0638aa8b
VAULT-23926: Fix rollback deadlock on perf secondaries (#25448)
* prevent deadlock

* rollbacks not done for sync invalidate

* add check for the path before deleting

* revert sync invalidation doesn't do rollbacks

* add known issue

* changelog

* fix formatting issue
2024-02-21 16:38:39 +01:00
Ben Ash
b163f4e818
Update docs for VSO v0.5.1 (#25530) 2024-02-20 19:14:16 -05:00
Austin Gebauer
66cdf14fe5
sync/gcp: documents project_id parameter for syncing with target projects (#25504) 2024-02-20 15:27:31 -08:00
Yoko Hyakuna
4fa9d46aef
[Docs] Add missing command doc for operator utilization (#25502)
* Add the CLI command for manual utilization reporting

* Remove extra space

* Empty-Commit
2024-02-20 13:33:13 -08:00
Scott Miller
e5c6e4cf13
Correct documentation that password generation uses entropy augmentation (#25332) 2024-02-20 12:03:13 -06:00
Austin Gebauer
6d4f5df69c
auth/jwt: adds documentation for multi-jwks config parameter (#25503)
* auth/jwt: adds documentation for multi-jwks config parameter

* updates bound_issuer parameter

* fix link
2024-02-20 08:49:53 -08:00
Mike Palmiotto
4707210b0b
Update old Default LCQ value (#25517) 2024-02-20 15:33:03 +00:00
Max Coulombe
b33e37df84
Docs/vault 23837/sync doc update (#25433)
* + documented the new sync API options
2024-02-17 14:58:50 -05:00
Peter Wilson
94fb339b31
VAULT-22483: Audit filter docs (#24903)
* Tidy up of files

* Add concepts page for filtering

* Update 'Common configuration options'

* Update table format (metrics)

* Filtering metrics

* audit specific filtering

* Fix nav and naming of files

* updates to audit filtering concept page

* Tweaks

* audit updates and glossary page addition for 'request'

* update CLI docs (audit enable)

* added metrics to 'all metrics' page

* fallback example and link fix

* improve links

* updated based on feedback

* some extra details on a request for glossary

* format fix

* use description on fallback device

* test message properties

* Sort out weird merge for events.mdx

* Update website/content/docs/concepts/filtering/audit.mdx

Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>

* Update website/content/docs/concepts/filtering/audit.mdx

Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>

* Update website/content/docs/concepts/filtering/audit.mdx

Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>

* Update website/content/docs/concepts/filtering/audit.mdx

Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>

* Update website/content/docs/concepts/filtering/audit.mdx

Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>

* Intro paragraph about filtering/normal devices, and uppercase bullets

* Fix casing on bullets and table layour

* Uppercase bullets

* Update website/content/docs/glossary.mdx

Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>

* Improvement?

* PR feedback

* Updated based on PR feedback

* Include common options

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Remove extra space

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Split out metrics

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Remove extra word

* Updated table formatting, remove close code block etc.

* Update website/content/docs/concepts/filtering/index.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

---------

Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>
Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-02-16 18:34:25 +00:00
Meggie
221cb24cdd
Clarify when external group membership is updated (#25455)
The large paragraph is hard to read and it's easy to miss crucial details around when membership in an external group will be updated.

Membership isn't updated when the configuration of the external group is changed, which can be counterintuitive.
2024-02-15 17:44:58 -05:00