%- include('top') %>
Mints a scoped OpenBao token confined to secret/apps/<name>/* for an external app. The token is shown once — record it in the app immediately; it cannot be recovered later.
The token is periodic: it stays valid as long as the app renews it within its period (POST /v1/auth/token/renew-self). If it lapses, mint a new one here — the app's policy and stored secrets are kept.
Give the external app this token (header X-Vault-Token) and the path convention below.
VAULT_ADDR=<%- vaultAddr %> path=secret/apps/<name>/conf curl "$VAULT_ADDR/v1/secret/data/apps//conf" \ -H "X-Vault-Token: <token above>"