...
In the above example, VaultConfigProvider will be passed the string "/run/secrets/vault-token" on initialization, which could be the filename for a Docker secret containing the initial Vault token, residing on the tmpfs mount, for instance. When resolving the value for "mysql.db.password", the VaultConfigProvider will use the path "vault_path" and the key "vault_db_password_key". The VaultConfigProvider would use this path and key to look up the corresponding secret. (VaultConfigProvider is a hypothetical example for illustration purposes only.)
...