Enable TLS verification for crds AuthEngineMount and JWTOIDCAuthEngineRole,

When enabling TLS verification for vault-config-operator's crds, the creation of crds AuthEngineMount and JWTOIDCAuthEngineRole, in the unit vault-oidc, fails.

The error is a communication error with openbao:

 Put "/v1/auth/kubernetes/login": unsupported protocol scheme ""

The priority of this issue is classified "medium" because these two crds are used by the vault-oidc unit enabling SSO only for the internal vault and, so, the risk induced by skipping TLS verification in tis case is acceptable.

Edited Nov 26, 2025 by Pierrick Seite
Assignee Loading
Time tracking Loading