更换策略令牌(Consul ACL Rotate a token)
翻译自: Secure Consul with Access Control Lists (ACLs)
转载请注明🙂,喜欢请一键三连哦 😊
一、背景
如果令牌泄漏,同样的策略(同样的规则列表)列表,我们可能要更换Token, 此时如何操作呢?
答: 通过Clone命令发生成同样权限的令牌, 然后删除旧的令牌,详细操作如下。
二、更换策略名牌
consul acl token clone -description "Clone of <token_you_are_cloning>" -id 6a1253d2-1785-24fd-91c2-f8e78c745511
响应结果如下:
Token cloned successfully.
AccessorID: dcfa52ed-9288-b3ff-056d-255ef69d2d88
SecretID: 0005d17e-5bb2-7e8b-7bfa-15f2eee9ad14
Description: Clone of Super User
Local: false
Create Time: 2018-10-22 16:26:02.909096 -0400 EDT
Policies:
00000000-0000-0000-0000-000000000001 - global-management
删除旧的Token:
consul acl token delete -id 6a1253d2-1785-24fd-91c2-f8e78c745511