An application needs a way to identify itself before it can retrieve passwords or other secrets from Vault. Boostport's Kubernetes Vault helper handled that initial login-token delivery for workloads in a cluster, using Vault's AppRole authentication method. It reduced the need to distribute a token manually to each application. This helper is no longer maintained and is distinct from Vault itself; a replacement must preserve the application's secret access and token-renewal behavior.
Current guidance
The Boostport/kubernetes-vault README says the project is no longer maintained because Vault now has native Kubernetes integration. It directs users toward Kubernetes authentication and the Vault Agent sidecar approach. This retirement applies to the Boostport helper, not to HashiCorp Vault itself.
An existing installation may depend on AppRole credentials, periodically renewed tokens and application-specific secret files. Inventory those dependencies before moving to a service-account-based login. Current Vault Kubernetes authentication validates Kubernetes tokens against configured roles; bound service accounts, namespaces, audiences and token-review configuration must match the actual cluster and Vault version.
Test token expiry, renewal, pod replacement and Vault unavailability with a narrowly privileged role. Verify how applications reload rotated secrets and whether credentials remain on disk after shutdown. Do not preserve an overly broad Vault policy merely to make a replacement login succeed. The maintainer’s recommended direction is verified, but it is not an automatic AppRole conversion or a tested migration recipe for every existing application.
Historical upstream link check · 2026-10-09
The recorded upstream address redirects to https://github.com/Boostport/kubernetes-vault/blob/main/README.md and returned HTTP 200 on 2026-10-09. GitHub marks Boostport/kubernetes-vault as archived. This confirms the repository's read-only archive state; any successor or supported distribution needs separate evidence. Link availability does not certify the historical installation instructions or current security support.
Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.
Historical Kubedex content
Preserved for context. Commands, versions, prices and results below reflect the original research.
The Kubernetes-Vault project allows pods to automatically receive a Vault token using Vault’s AppRole auth backend.
Highlights
- Secure by default. The Kubernetes-Vault controller does not allow using root tokens to authenticate against Vault.
- Prometheus metrics endpoint over http or https, with optional TLS client authentication.
- Supports using Vault as a CA or an external CA for all components with TLS support.
- High availability mode using Raft, so that if the leader goes down, a follower can take over immediately.
- Peer discovery using Kubernetes services and endpoints and gossip to propagate peer changes across the cluster.
Prerequisites:
- Vault should be 0.6.3 and above.
- You must use Kubernetes 1.6.0 and above as we rely on init containers (in beta) to accept the token.
- For Kubernetes 1.5.x and below, please use an older version of Kubernetes-Vault by referencing the compatibility table.
- You must generate a periodic token with the correct policy to generate secret_ids using the AppRole backend.
- The Kubernetes-Vault controller uses the Kubernetes service account to watch for new pods. This service account must have the appropriate permissions.
- Your app should use a Vault client to renew the token and any secrets you request from Vault.
- You should configure Vault to use HTTPS so that the authentication token and any other secrets cannot be sniffed.
- If using RBAC, the Kubernetes-Vault controller needs the following permissions
- get its endpoint (headless service)
- list and watch pods in all namespaces
Kubernetes-Vault uses Prometheus for metrics reporting. It exposes these metrics over the /metrics endpoint over http or https. This project is licensed under the Apache 2 License.
Sources & further reading
Spotted something that needs another look?
Help improve this page →