350 Commits

Author SHA1 Message Date
Guilherme Santos
7c3da302c1
docs: remove venafi plugin documentation (#30682)
Remove documentation for the Venafi plugin. This change aligns with the
standard approach of having third-party plugins host and maintain their
own documentation (e.g., KeyFactor, AppviewX).

Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>
2025-05-20 10:30:47 -07:00
drewmullen
6e67294f4f
Terraform secret engine docs - support multiple team tokens (#30477)
* include docs for multi team tokens

* separate legacy team and org token docs

* update to reflect system max_ttl behavior

* Update website/content/docs/secrets/terraform.mdx

Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>

* Update website/content/docs/secrets/terraform.mdx

Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>

* Update website/content/docs/secrets/terraform.mdx

Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>

* Update website/content/docs/secrets/terraform.mdx

---------

Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>
2025-05-20 08:11:12 -07:00
Yoko Hyakuna
fd5c044c82
Update the tutorial links (#30630) 2025-05-14 15:22:41 -07:00
Yoko Hyakuna
4ea56609b1
Remove the out-dated statement about HCP Terraform (#30616) 2025-05-14 13:52:52 -07:00
Luis (LT) Carbonell
ed52371b10
Upgrade FIPS 1402 -> 1403 (#30576)
* Upgrade FIPS 1402 -> 1403

* Clean up

* changelog
2025-05-12 15:01:30 -05:00
nphilbrook
6852fc4e60
Fixing link to static role documentation (#30486)
* Created branch nphilbrook_aws_static_role_docs_link from main

* Correcting anchor link

* Changelog entry

* Removing changelog
2025-05-12 12:12:36 -07:00
Sarah Chavis
485ccbc5da
[DOCS] IA refresh (phase 2) (#30287) 2025-04-29 17:08:14 -07:00
Robert
bf339bc50d
Add snowflake DB API warning (#30327)
* Add API warning based on DB type

* Add deprecation notice

* Add warning to the top of the docs pages

* Update capabilities table

* Filter SQLConnectionProducer fields from unrecognized parameters warning

* Add test case
2025-04-28 13:05:55 -05:00
Yoko Hyakuna
a0b52b4a82
[Docs] Promote HVS as an alternative solution (#30141)
* Promote HVS as an alternative solution

* Update website/content/partials/tips/try-hvs.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2025-04-01 11:48:13 -07:00
Thy Ton
a0a8cfa8b0
docs: fix enterprise Oracle plugin instant client version (#30115) 2025-03-31 11:12:06 -07:00
Thy Ton
5f99abe101
add docs for Enterprise Oracle database plugin with instant client table (#30106)
---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
Co-authored-by: helenfufu <25168806+helenfufu@users.noreply.github.com>
2025-03-28 15:53:54 -07:00
Sarah Chavis
4383f5bb9c
make AD secrets plugin EOL (#29923) 2025-03-13 15:14:36 -07:00
Milena Zlaticanin
d9ea865a84
Updating docs to include new assume role fields (#29649)
* Add assume role fields in docs

* add sample response + note about the new feature

* Add a cross-account section in docs

* Update website/content/api-docs/secret/aws.mdx

Co-authored-by: John-Michael Faircloth <fairclothjm@users.noreply.github.com>

* Update website/content/docs/secrets/aws.mdx

Co-authored-by: John-Michael Faircloth <fairclothjm@users.noreply.github.com>

* Update website/content/docs/secrets/aws.mdx

Co-authored-by: John-Michael Faircloth <fairclothjm@users.noreply.github.com>

* Update website/content/docs/secrets/aws.mdx

Co-authored-by: John-Michael Faircloth <fairclothjm@users.noreply.github.com>

* Update website/content/docs/secrets/aws.mdx

Co-authored-by: Robert <17119716+robmonte@users.noreply.github.com>

* Update website/content/docs/secrets/aws.mdx

Co-authored-by: Robert <17119716+robmonte@users.noreply.github.com>

* Update website/content/api-docs/secret/aws.mdx

Co-authored-by: Robert <17119716+robmonte@users.noreply.github.com>

* Update website/content/api-docs/secret/aws.mdx

Co-authored-by: Robert <17119716+robmonte@users.noreply.github.com>

* update

* Update website/content/api-docs/secret/aws.mdx

Co-authored-by: Robert <17119716+robmonte@users.noreply.github.com>

* Update website/content/docs/secrets/aws.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/secrets/aws.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/api-docs/secret/aws.mdx

Co-authored-by: Robert <17119716+robmonte@users.noreply.github.com>

* update

* Update website/content/docs/secrets/aws.mdx

Co-authored-by: Robert <17119716+robmonte@users.noreply.github.com>

* update

---------

Co-authored-by: John-Michael Faircloth <fairclothjm@users.noreply.github.com>
Co-authored-by: Robert <17119716+robmonte@users.noreply.github.com>
Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2025-03-10 12:05:51 -07:00
Yash Khemani
c74154c098
docs: enable aws secrets engine, not gcp (#29856) 2025-03-06 14:07:15 -08:00
Robert
35af160994
Add docs for GCP automated root rotation (#29782)
* Fix azure reference

* Add gcp docs

* Fix auth references
2025-03-04 11:58:13 -06:00
Thy Ton
6d9543158d
add docs for external Enterprise plugins (#29738)
---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2025-02-27 16:00:23 -08:00
vinay-gopalan
1091474e4d
Add docs for scheduled root rotation feature for the AWS and DB engines (#29755) 2025-02-27 15:48:47 -08:00
kpcraig
8497dc66d0
Add docs for plugins with enterprise scheduled root rotation feature (#29608) 2025-02-27 10:44:36 -08:00
Angel Garbarino
513e9804ee
[DOCS] Add GUI for Azure/AWS/GCP Secret Engines configuration (#29647)
* wip

* finish azure docs

* some fixes

* get role heading to where it was

* Apply suggestions from code review

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update website/content/docs/secrets/azure.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* pr comments

* add aws

* gcp configuration

* fix formatting

* remove indents for parser

* formatting fixed?

* Update website/content/docs/secrets/gcp.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* try again

* might be the end of me

* tried running npm run format and got some promising results

* missed

* this should work

* numbering fixes

* Apply suggestions from code review

add group="gui"

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

* Update azure.mdx

change heading to match

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2025-02-27 10:49:58 -07:00
Victor Rodriguez
b28ba3046f
Document new PKI CMPv2 configuration field disabled_validations (#29707)
* Document new PKI CMPv2 configuration field disabled_validations.
2025-02-27 09:13:30 -08:00
Yoko Hyakuna
5d1a971c44
Add missing '**' to the prereq (#29696) 2025-02-24 11:14:20 -08:00
John-Michael Faircloth
04e75372fb
database/mssql: set default root rotation stmt for contained db (#29399)
* database/mssql: set default root rotation stmt for contained db

* changelog

* add rotate root test

* fix test

* update passwords to make mssql happy

* create admin user

* update contained user create query

* remove test
2025-01-24 15:42:27 -05:00
Merouane Atig
4ff9bdba90
Fix typo: compatability => compatibility (#29372)
* Fix typo in awskms.mdx

* Fix typo in Makefile

* Fix typo in gcpkms/index.mdx

---------

Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>
2025-01-21 12:49:36 -05:00
swati
e69f2ace06
Fix Static Role Name Consistency in PostgreSQL Configuration (#29138)
* Updated the PostgreSQL database creation command to ensure the static role name is consistent.

The role name specified in allowed_roles="my-role" under the section "Rootless Configuration and Password Rotation for Static Roles" should align with the static role name in step #3. Previously, the command incorrectly used "my-static-role"; it should be "my-role" to match the earlier step.

The same role name should also be used when reading the static credentials in step #4

* Added the file changelog/29138.txt

* Delete changelog/29138.txt

---------

Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>
Co-authored-by: akshya96 <87045294+akshya96@users.noreply.github.com>
Co-authored-by: Violet Hynes <violet.hynes@hashicorp.com>
2025-01-16 16:05:20 -05:00
Moritz Rathberger
4536c987d9
fixed typo in kv v1 upgrade docs (#29361) 2025-01-16 14:41:58 -05:00
John-Michael Faircloth
a0ecbe993c
docs: DB skip auto import rotation (#29098)
* docs: DB skip auto import rotation

* add usage section

* add password field; mark self_managed_password as deprecated
2025-01-10 16:17:36 -06:00
Rachel Culpepper
75ddf6e4ed
Add docs for ML-DSA and hybrid keys (#29246)
* add api docs for pqc key types

* add pqc key types to docs

* remove slh-dsa and add hybrid
2025-01-09 14:57:29 -06:00
Victor Rodriguez
b9e949bf73
Support all fields of the name constraints extension when generating CA certificates (#29245)
Support all fields of the name constraints extension when generating CA certs.

The PKI secrets engine only provided parameter permitted_dns_domains to create
the name constraints extension when generating CA certificates.

Add the following parameters to provide full support for the extension:

  * permitted_email_addresses
  * permitted_ip_ranges
  * permitted_uri_domains
  * excluded_dns_domains
  * excluded_email_addresses
  * excluded_ip_ranges
  * excluded_uri_domains

Specifying any combination of these parameters will trigger the creation of the
name constraints extension as per RFC 5280 section 4.2.1.10.
2024-12-20 14:55:25 -05:00
Yoko Hyakuna
32ba53f3c4
[DOCS] Update the PKI secrets engine docs title & description (#29136)
* Update the PKI secrets engine docs title & description

* Update website/content/docs/secrets/pki/index.mdx

Co-authored-by: Jonathan Frappier <92055993+jonathanfrappier@users.noreply.github.com>

* Incorporate the review feedback

---------

Co-authored-by: Jonathan Frappier <92055993+jonathanfrappier@users.noreply.github.com>
2024-12-19 14:36:16 +01:00
Yoko Hyakuna
f975259267
[DOCS] Update the title & description for SEO improvement (#29115)
* Update the title & description for SEO improvement

* Minor updates for style consistency

* Revert back the change

* Update website/content/docs/secrets/aws.mdx

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-12-18 15:37:38 -08:00
Yoko Hyakuna
8aa6fa3a90
[DOCS] Update the page description for SEO improvement #2 (#29116)
* Update the page description for SEO improvement

* Update the description for SEO improvement

* Update the description

* Update website/content/docs/secrets/transform/ff3-tweak-details.mdx

Co-authored-by: Jonathan Frappier <92055993+jonathanfrappier@users.noreply.github.com>

* Fixing a typo

* Incorporate review feedback

---------

Co-authored-by: Jonathan Frappier <92055993+jonathanfrappier@users.noreply.github.com>
2024-12-18 17:35:57 -06:00
Yoko Hyakuna
732837b082
[DOCS] Match the page_title and H1 header (#29192)
* Match the page_title and H1 header

* Update website/content/docs/secrets/databases/index.mdx

Co-authored-by: Brian Shumate <brianshumate@users.noreply.github.com>

---------

Co-authored-by: Brian Shumate <brianshumate@users.noreply.github.com>
2024-12-16 08:52:59 -08:00
Yoko Hyakuna
c4be16c8f7
[DOCS] Update the page description for SEO improvement #4 (#29166)
* Update the page description to improve SEO

* Minor updates

* Update setup.mdx

* Update setup.mdx

* Update website/content/docs/secrets/ad/migration-guide.mdx

Co-authored-by: Jonathan Frappier <92055993+jonathanfrappier@users.noreply.github.com>

* Update website/content/docs/secrets/ad/index.mdx

Co-authored-by: Jonathan Frappier <92055993+jonathanfrappier@users.noreply.github.com>

* Update website/content/docs/secrets/ad/index.mdx

Co-authored-by: Jonathan Frappier <92055993+jonathanfrappier@users.noreply.github.com>

---------

Co-authored-by: Jonathan Frappier <92055993+jonathanfrappier@users.noreply.github.com>
2024-12-12 09:01:31 -08:00
claire bontempo
bc09d9acec
Docs: Add updated screenshots to kv subkey docs (#29067)
* clarify subkey read in GUI

* add screenshots

* add to index

* update kv nav steps

* update alt text for screenshot

* update steps

* edits

* fix build error and simplify path structure

* fix paths

* missed one

* missed another one >_<

* Update website/content/docs/secrets/kv/kv-v2/cookbook/write-data.mdx

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-12-04 12:14:08 -08:00
claire bontempo
dc343f3566
add read subkeys to kv patch docs (#29028)
* add read subkey to docs

* TW edits

* fix copy/paste error

* correct nil --> null for API results

* make example data match between CLI and API (1 of 2)

* make example data match between CLI and API (2 of 2)

---------

Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com>
2024-11-27 16:03:18 -08:00
Victor Rodriguez
48cec9729d
Enforce PKI issuer constraints. (#29045)
Add environment variable VAULT_DISABLE_PKI_CONSTRAINTS_VERIFICATION.

Setting VAULT_DISABLE_PKI_CONSTRAINTS_VERIFICATION=true will disable the cert
issuance/signing verification.
2024-11-27 18:34:26 +01:00
Victor Rodriguez
b2886d2a99
Revert "Perform validation when issuing or signing certificates. (#28921)" (#29041)
This reverts commit 31fc51c68fb4591ece3dcdd6fd7a8f4b18b465fa.
2024-11-27 16:22:20 +00:00
Victor Rodriguez
31fc51c68f
Perform validation when issuing or signing certificates. (#28921)
Add environment variable VAULT_DISABLE_ISSUING_VERIFICATION.

Setting VAULT_DISABLE_ISSUING_VERIFICATION=true will disable the cert
issuance/signing verification.
2024-11-27 13:23:07 +00:00
Mitch Pronschinske
5dee624657
[DOCS] Fix wrong casing of "key-value" on the KV secrets engine page (#28970) 2024-11-21 12:14:09 +00:00
kevin-loehfelm
50cc886e46
Update typo in AWS Secrets Engine documentation (#28930)
Co-authored-by: Kuba Wieczorek <kuba.wieczorek@hashicorp.com>
2024-11-19 15:14:08 +00:00
Sarah Chavis
1b419330e3
updates screenshots and add ent alert (#28934) 2024-11-18 11:39:19 -08:00
Sarah Chavis
cb0448a785
[DOCS] Refresh kv docs (#28919)
* refresh kv docs

* apply feedback and add missing API instructions
2024-11-15 17:06:26 -08:00
Yoko Hyakuna
dc40b23d9a
[Docs] Move the tutorial content to the docs (#28894)
* Move the tutorial content to the docs

* Split the usage doc from the overview

* Change 'Key Management' to 'key management' where appropriate
2024-11-15 09:05:30 -08:00
Jonathan Frappier
1a43ff6755
Remove deprecated tutorial links (#28905) 2024-11-13 15:26:38 -05:00
Jonathan Frappier
47eeeb7996
Add steps from IBM Db2 tutorial (#28879) 2024-11-12 09:39:49 -05:00
Gabriele Olla
ea3002fd30
Add iam:GetUser action for IAM Policy to AWS docs (#28788)
* add iam:GetUser action on split policy

Signed-off-by: Olla Gabriele <gabriele.olla@prima.it>
2024-11-12 09:28:33 -05:00
Martin
c38c5763ed
Fix: Add missing iam:TagUser permission (#28757)
Co-authored-by: Yoko Hyakuna <yoko@hashicorp.com>
2024-11-04 09:20:37 -08:00
Steven Clark
e489631e87
Transit: Allow ENT only arguments for sign/verify. Add docs for new Ed25519 signature types (#28821) 2024-11-01 12:57:52 -04:00
Scott Miller
415d260995
Support trimming trailing slashes via a mount tuneable to support CMPv2 (#28752)
* Support trimming trailing slashes via a mount tuneable to support CMPv2

* changelog/

* Perform trimming in handleLoginRequest too

* Eagerly fetch the mount entry so we only test this once

* Add a mount match function that gets path and entry

* Update vault/request_handling.go

Co-authored-by: Steven Clark <steven.clark@hashicorp.com>

* more docs

* Some patches (from ENT) didnt apply

* patch fail

* Update vault/router.go

Co-authored-by: Steven Clark <steven.clark@hashicorp.com>

* PR feedback

* dupe

* another dupe

* Add support for enabling trim_request_trailing_slashes on mount creation

* Fix read mount api returning configuration for trim_request_trailing_slashes

* Fix test assertion

* Switch enable and tune arguments to BoolPtrVal to allow end-users to specify false flag

* Add trim-request-trailing-slashes to the auth enable API and CLI

---------

Co-authored-by: Steven Clark <steven.clark@hashicorp.com>
2024-10-24 10:47:17 -05:00
Scott Miller
c41f5bdcb4
Document the encryption algorithms used in ADP auditing purposes (#28691) 2024-10-15 11:56:16 -05:00