We would like to use Hashicorp Vault to manage our secrets and access these secrets form within Pipelines. This can be done via the Vault REST API using a Vault token as authentication. The token can be stored as a repository variable, so it's available during the build.
However, as it is best practice, tokens have a limited life time and need to be rotated. How can I rotate Vault tokens? Is there a cronjob like service / integration that could be used?