How do people handle refreshing secrets on servers which maintain a connection to a database once their creds expire?
How do people handle refreshing secrets on servers which maintain a connection to a database once their creds expire?
If you are able to change your application's code, you could integrate with vault's API directly which is the most clean solution. If you are unable, you can use [consul-template](https://github.com/hashicorp/consul-template) or [envconsul](https://github.com/hashicorp/envconsul) to securely introduce your secret which would entail reloading/restarting your application.
I look forward to other answers though, if anyone's currently set this up. I haven't used it yet myself, but I've been considering it.
In that situation I would check out periodic tokens[0] since they live as long as they're renewed within the TTL.
0. https://www.vaultproject.io/docs/concepts/tokens.html#period...
TOKENS however do get killed at the end of their TTL. But you can renew tokens forever if you allow for that.