You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Vault
Good day,
I'm trying to investigate what is in place on a vault that I'm working with. How do I see what users there are and which policies they hold?
On a possibly related note, when is the next release? I see the 'list' support went in, and that may solve my issue above.
--
Zach
Jeff Mitchell
unread,
Jan 25, 2016, 11:04:59 PM1/25/16
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to vault...@googlegroups.com
Hi there,
Can you describe what you mean by "list users"? If you mean "list
tokens" this is not something we plan to support, for security
reasons. However, over time support for listing users or apps
configured into various backends (e.g. username/password or app-id)
should appear, and you can then query those to find out which policies
they are giving out for successfully authenticated clients.
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Vault
I'm primarily after the ability to determine what app_ids/users exist in the system, and which policies they are attached to. The affect of which should be something like "who has access to what".
Armon Dadgar
unread,
Jan 26, 2016, 12:56:00 PM1/26/16
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to vault...@googlegroups.com, zle...@womply.com
Hey,
We are getting the list operation support into Vault 0.5 which extends
the core (client, API, ACLs, etc) to all support it and only the generic and
cubbyhole backends initially. With future releases we will be adding list
support to all the backends, and then you should just be able to use list
to see the existing users and app IDs. Hope that helps!
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Armon Dadgar, vault...@googlegroups.com
On Tue, Jan 26, 2016 at 09:55:28AM -0800, Armon Dadgar wrote:
>Hey,
>
>We are getting the list operation support into Vault 0.5 which extends
>the core (client, API, ACLs, etc) to all support it and only the generic and
>cubbyhole backends initially. With future releases we will be adding list
>support to all the backends, and then you should just be able to use list
>to see the existing users and app IDs. Hope that helps!
Thanks for the information. I think thats what I'm after. Any timeline
on when that will be released/stable?
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Zach Leslie, vault...@googlegroups.com
Zach,
Vault 0.5 will be released in the next few weeks, and then future versions of Vault
will expand support to the all backends over time. Hope that helps!
Best Regards,
Armon Dadgar
Jeff Mitchell
unread,
Jan 26, 2016, 7:53:22 PM1/26/16
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to vault...@googlegroups.com
Hi Zach,
Not at this point. The initial listing support will be in 0.5, and
listing of various other items will come over time as we get the
chance to code it in. PRs from interested parties will certainly help!
--Jeff
> --
> This mailing list is governed under the HashiCorp Community Guidelines -
> https://www.hashicorp.com/community-guidelines.html. Behavior in violation
> of those guidelines may result in your removal from this mailing list.
>
> GitHub Issues: https://github.com/hashicorp/vault/issues > IRC: #vault-tool on Freenode
> --- You received this message because you are subscribed to the Google
> Groups "Vault" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to vault-tool+...@googlegroups.com.
> To view this discussion on the web visit