問題文
A scheduler creates Vault tokens on behalf of the jobs it launches and needs a way to revoke each job's token when the job finishes, without keeping the token values themselves. What should it store, and what can it do with what it stores?
選択肢
- The token value itself in an encrypted form, since the accessor only identifies the auth mount that issued the token and cannot be used to act on an individual token.
- The accessor returned alongside each token, which can be used to look up the token's properties, look up its capabilities, renew it, and revoke it.
- The accessor, which can be presented in place of the token when calling any endpoint, so the scheduler can also verify that the job's credentials still work.
- A hash of each token value, which the revocation endpoint accepts in place of the value itself.