A developer runs the commands shown in the exhibit. After renewing the lease, the lease_duration remains 1 hour. What is the most likely reason?
Exhibit
Refer to the exhibit. ``` $ vault read database/creds/my-role Key Value --- ----- lease_id database/creds/my-role/abc123... lease_duration 1h lease_renewable true password ... username v-token-my-role-... $ vault lease renew database/creds/my-role/abc123... Key Value --- ----- lease_id database/creds/my-role/abc123... lease_duration 1h lease_renewable true ```
Trap 1: The lease is not renewable.
The output shows lease_renewable: true.
Trap 2: The mount's max_lease_ttl is set to 1h.
This could also limit renewal, but the role's max_ttl is more likely.
Trap 3: The developer does not have permission to renew the lease.
The renewal command succeeded, so permission is not an issue.
- A
The lease is not renewable.
Why it fails: The output shows lease_renewable: true.
- B
The mount's max_lease_ttl is set to 1h.
Why it fails: This could also limit renewal, but the role's max_ttl is more likely.
- C
The developer does not have permission to renew the lease.
Why it fails: The renewal command succeeded, so permission is not an issue.
- D
The role's max_ttl is set to 1h.
Vault caps the lease duration at the role's max_ttl. Even when renewal requests a longer period, the returned lease_duration cannot exceed that ceiling, so a 1h max_ttl keeps it at 1 hour regardless of the requested increment.