Which user should run vault agent?

should vault agent service run as root or vault user?

Having a dedicated user is a much more secure option, especially since the agent can execute commands as part of template rendering.

Cheers,
Grant