-
Type:
Bug
-
Resolution: Unresolved
-
Priority:
Blocker
-
Component/s: conjur-credentials-plugin
-
Environment:PRODUCTION
Hi Jenkins Support,
I have installed Conjur Secrets Plugin V3.0.6 in my jenkins instance to retrieve the credentials from cyberark.
I have ended up in the issue where kid/keys json is null when hitting the url of form http://<jenkins instance name>/jwtauth/conjur-jwk-set
Because of this, the integration between cyberark and Jenkins is breaking.
For the first time I was able to retrieve the credes from cyberark. But when the kid is changed/null, the connection breaks.
From my observations, following are the causes of kid becoming null/changing:
- when Signing Key Lifetime In Minutes expires
- when some restart/reboot/any actions happen on server/service level from infra
Note: After null, its taking some time to generate the json. Sometimes it tool 3 hours, 17.5 hours, 3 days. So the time taken was also not constant, which is blocking us from at least proceeding with some dynamic kid retrieval from cyberark side.
When referred to documents, it says there is some bug w.r.t no file write/ memory persist and suggested to create folders manually.
I have tried creating folders manually with the following names in our instance:
- jwt-keys
- jwt-secrets
- jwtauth-keys
But no change.
ATM, I'm blocked with this issue to proceed further on this integration.
Can you please help me here.
Please feel free to reach me if you need any additional information.
Thanks,
Sreelekha