問題文
A batch job runs on a fleet of virtual machines with no cloud provider identity available and no Kubernetes involved. It must obtain a Vault token at startup without a human typing anything, and the operator wants to be able to hand out credentials that expire on their own if a machine is decommissioned. Which approach fits?
選択肢
- Use the token method with a long-lived token written into the startup script, since the token method is the only one that cannot be disabled.
- Use the username and password method, storing the password in the machine image so that every instance can log in.
- Use the certificate method with one shared client certificate installed on the image, so that all machines present the same identity and the operator only has to manage a single certificate.
- Use the machine-oriented method that combines a role identifier with a secret identifier, and give the secret identifier a limited number of uses and a short validity period.