Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Vault offline installation #1371

Conversation

erzetpe
Copy link
Contributor

@erzetpe erzetpe commented Jun 17, 2020

No description provided.

@erzetpe erzetpe merged commit 55cce2e into hitachienergy:feature/vault-mvp Jun 17, 2020
ar3ndt pushed a commit to ar3ndt/epiphany that referenced this pull request Jun 22, 2020
sk4zuzu pushed a commit to sk4zuzu/epiphany that referenced this pull request Jun 22, 2020
ar3ndt pushed a commit that referenced this pull request Jun 22, 2020
erzetpe added a commit that referenced this pull request Jun 26, 2020
* Fix of configure-vault script

* Move initialize vault to script, change unseal logic

* Add checking if vault has been unsealed properly and turning kubernetes authentication automatically with kubernetes integration.

* Add userpass authentication and default policies

* Adding users to userpass authentication

* Add user creation for userpass authentication

* Add user creation for userpass authentication - ansible part

* Fix issue when no users authenticating via userpass are added to vault

* Add users section to default and setting log level for vault

* Kubernetes configuration and integration

* Fix issue with path to helm in configure-vault.sh script

Add TODOs

* Add TODO, create application service account for integration with kubernetes

* Add TODO, add missing service account template for application authentication

* Change location of log files

* Change policy to expose configurable endpoints

* Create policies folder for config, change vault secret variable name

* Add setting to clean of token helper disable/enable

* Change setting limits for core dumps, add flag to override existing users

* Add parameters to override existing vault users in vault

* Add Vault symlink to PATH accessible directory

* Add timestamp and changed configure_vault log location

Fix typo

* Changes related to code review

* Change name of function check_vault_error and add errors catching to kubectl invocations

* Add option to unseal vault with script after restart, cosmetic change to configure-vault.sh

* Add contidional option to unseal vault with script after restart, separate autounseal from autoconfiguration option

Change counter naming in unseal-vault.sh script, change error handling

Remove todos, run user creation only, when specified in Epiphany configuration, change default provisioner user name

Fixes and additional logging

* add tls support for vault

* Add namespaces support, disable/enable ui, clean defaults file

* Fixes to task names

* fixes

* Fix issues with starting service with UI turned off and config UI setting

* Add Vault offline installation (#1371)

* Fixes after code review

* Change hardcoded policy files to templates

* Fix issue with token path

* Vault: Update shell scripts

* Review: shell scripts

* Rename certificate_generate.yml

* Changes after review

* vault audit empty list status code ignored

* - Added vault for single machine installation.

* fix offline vault helm installation

* fix offline vault installation and custom values bug

* vault: adding proper fix for the "new cluster problem" (#1384)

* vault selfsigned cert parametrized in config

* cault selfsigned cert set country US

Co-authored-by: Tomasz Arendt <[email protected]>
Co-authored-by: to-bar <[email protected]>
Co-authored-by: Luuk van Venrooij <[email protected]>
Co-authored-by: Michał Opala <[email protected]>
@erzetpe erzetpe deleted the feature/vault-mvp-offline-install branch January 28, 2021 14:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants