How does the application know to use the updated secret within HashiCorp Vault?

For Consul as storage backend this could be a solution