Vault Configuration

The chart uses External Secrets Operator, not direct Vault API calls. Configure an existing SecretStore/ClusterSecretStore, externalSecrets.remoteKey, and refresh interval. The checked-in overrides use store name slack-kb-agent-secretstore; remote keys are environment-specific.

The ExternalSecret maps named properties to an opaque Kubernetes Secret. Required properties vary by runtime and enabled integrations; use Environment variables and the template as the definitive list. Never put values in Helm files or documentation.

Before deployment, confirm the operator can read the remote key and that the generated Secret contains the expected keys. The Vault authentication method, policies, administrators, rotation cadence, and recovery process are TO_BE_CONFIRMED. Rotating TOKEN_ENCRYPTION_KEY requires migration or reconnection of stored user credentials.