HashiCorp Vault
HashiCorp's Vault configuration file
vault.jsonvault.config.json
Validate
Check your file against this schema
Opens the validator with this schema already loaded. Paste your
vault.json and it validates in your browser — nothing is uploaded.
Reference
Fields
Generated directly from the schema, following local
$refs, to two levels of nesting.
| Field | Type | Description |
|---|---|---|
api_addr | string | Specifies the address (full URL) to advertise to other Vault servers in the cluster for client redirection. This can also be provided via the environment variable VAULT_API_ADDR. |
cache_size | string | Specifies the size of the read cache used by the physical storage subsystem. The value is in number of entries, so the total cache size depends on the size of stored entries. default: "131072" |
cluster_addr | string | Specifies the address to advertise to other Vault servers in the cluster for request forwarding. This can also be provided via the environment variable VAULT_CLUSTER_ADDR. |
cluster_name | string | Specifies a human-readable identifier for the Vault cluster. If omitted, Vault will generate a value. |
default_lease_ttl | string | Specifies the default lease duration for tokens and secrets. This is specified using a label suffix like '30s' or '1h'. default: "768h" |
default_max_request_duration | string | Specifies the default maximum request duration allowed before Vault cancels the request. default: "90s" |
detect_deadlocks | string | A comma separated string that specifies the internal mutex locks that should be monitored for potential deadlocks. |
disable_cache | boolean | Disables all caches within Vault, including the read cache used by the physical storage subsystem. default: false |
disable_clustering | boolean | Specifies whether clustering features such as request forwarding are enabled. default: false |
disable_mlockrequired | boolean | Stops Vault from executing the mlock syscall, which prevents memory from being swapped to disk. This can also be provided via the environment variable VAULT_DISABLE_MLOCK. |
ha_storage | object | — |
introspection_endpoint | boolean | Enables the sys/internal/inspect endpoint which allows users with a root token or sudo privileges to inspect certain subsystems inside Vault. default: false |
listenerrequired | array<object> | — |
log_level | oneOf | Specifies the log verbosity level default: "info" |
max_lease_ttl | string | Specifies the maximum possible lease duration for tokens and secrets. default: "768h" |
pid_file | string | Path to the file in which the Vault server's Process ID (PID) should be stored. |
plugin_directory | string | A directory from which plugins are allowed to be loaded. |
raw_storage_endpoint | boolean | Enables the sys/raw endpoint which allows the decryption/encryption of raw data into and out of the security barrier. default: false |
seal | array<object> | — |
storagerequired | object | — |
telemetry | object | — |
telemetry.prometheus_retention_time | string | Specifies the retention time for Prometheus metrics. default: "0" |
telemetry.disable_hostname | boolean | If true, the hostname will not be prefixed to metrics. default: false |
telemetry.dogstatsd_addr | string | The address of a DogStatsD agent. |
ui | boolean | Enables the built-in web UI. default: false |
Audit
What we found in this schema
- Declared draft: draft-07
- Validates cleanly against its own meta-schema.
- 103 properties, 84% carrying a description, max nesting depth 12.
Standards
Specification sections for the keywords in this schema
| Keyword | Document | Section |
|---|---|---|
$id | JSON Schema Core, draft 2020-12 | §8.2.1 — The "$id" Keyword |
$ref | JSON Schema Core, draft 2020-12 | §8.2.3.1 — Direct References with "$ref" |
$schema | JSON Schema Core, draft 2020-12 | §8.1.1 — "$schema" |
const | JSON Schema Validation, draft 2020-12 | §6.1.3 — "const" |
default | JSON Schema Validation, draft 2020-12 | §9.2 — "default" |
description | JSON Schema Validation, draft 2020-12 | §9.1 — "title" and "description" |
items | JSON Schema Core, draft 2020-12 | §10.3.1.2 — "items" |
oneOf | JSON Schema Core, draft 2020-12 | §10.2.1.3 — "oneOf" |
properties | JSON Schema Core, draft 2020-12 | §10.3.2.1 — "properties" |
required | JSON Schema Validation, draft 2020-12 | §6.5.3 — "required" |
type | JSON Schema Validation, draft 2020-12 | §6.1.1 — "type" |
Documents
- JSON Schema Core, draft 2020-12 — JSON Schema: A Media Type for Describing JSON Documents, A. Wright, H. Andrews, B. Hutton, G. Dennis, Eds., 2022. draft-bhutton-json-schema-01. An expired Internet-Draft with no formal standing in the IETF standards process; it is nonetheless the specification of record for JSON Schema 2020-12, published by json-schema.org.
- JSON Schema Validation, draft 2020-12 — JSON Schema Validation: A Vocabulary for Structural Validation of JSON, A. Wright, H. Andrews, B. Hutton, Eds., 2022.
- RFC 8259 (STD 90) — The JavaScript Object Notation (JSON) Data Interchange Format, T. Bray, Ed., 2017. The format a schema describes.
- RFC 6901 — JavaScript Object Notation (JSON) Pointer. Defines the pointer syntax used by $ref fragments and the ~0 / ~1 escapes.
Source
Attribution
This schema comes from SchemaStore, distributed under the Apache License 2.0. Copyright 2015–present Mads Kristensen and contributors. View the original file. The field table and audit on this page are generated by JSONTools.tools; the schema itself is unmodified.