SpringBoot无法从Vault通用路径读取密钥问题求助
Looks like the core issue here is that you're using Vault's KV Version 2 engine (clear from your vault secrets list output showing map[version:2] for the kv/ path), but your Spring Cloud Vault configuration is still set up for KV Version 1. KV v2 uses a different internal path structure than v1, which is why your app is falling back to the default placeholder values instead of pulling secrets from Vault.
Let's fix this step by step:
1. Update bootstrap.yml for KV Version 2
Remove the generic configuration block entirely (it's designed for KV v1) and properly configure the KV v2 settings. Here's the corrected config:
spring: cloud: vault: scheme: http host: <HOSTIP> port: 8200 connection-timeout: 5000 read-timeout: 15000 authentication: TOKEN token: <TOKEN> kv: enabled: true backend: kv # Explicitly declare we're using KV version 2 version: 2 # Point directly to the path where your secrets are stored: kv/demo/dev default-context: demo/dev logging: level: ROOT: WARN
If you want to use Spring profiles to load environment-specific secrets (e.g., activate the dev profile to pull from kv/demo/dev), adjust the config like this instead:
spring: cloud: vault: scheme: http host: <HOSTIP> port: 8200 connection-timeout: 5000 read-timeout: 15000 authentication: TOKEN token: <TOKEN> kv: enabled: true backend: kv version: 2 default-context: demo # Use '/' to separate the base context from the profile suffix profile-separator: '/' # Activate the dev profile to match your secret path profiles: active: dev
2. Verify Your Vault Secrets Are Accessible
Run this command to confirm your secrets are stored correctly at the expected path:
vault kv get kv/demo/dev
You should see your spring.datasource.username and spring.datasource.password values in the output.
3. Clean Up Your Application Code (Optional)
Your other.username field is showing the placeholder value because you didn't store that key in Vault. You have three options here:
- Add the secret to Vault with
vault kv put kv/demo/dev other.username=your-desired-value - Remove the
@Value("${other.username}")field from your code - Set a default value for the field like
@Value("${other.username:default-user}")
Why Did Filesystem Integration Work Before?
Filesystem configs use a flat path structure that matches KV v1's behavior. KV v2 adds an internal /data/ segment to the API path (your kv/demo/dev is actually stored at kv/data/demo/dev under the hood), so Spring Cloud Vault needs explicit configuration to handle this version-specific difference.
内容的提问来源于stack exchange,提问作者Subodh Joshi

