2015-07-18 15:30:30 +08:00
|
|
|
vault
|
|
|
|
=====
|
|
|
|
|
2015-07-18 15:44:59 +08:00
|
|
|
![](https://badge.imagelayers.io/vimagick/vault:latest.svg)
|
|
|
|
|
2015-07-18 15:30:30 +08:00
|
|
|
[`Vault`][1] is a tool for securely accessing secrets. A secret is anything
|
|
|
|
that you want to tightly control access to, such as API keys, passwords,
|
|
|
|
certificates, and more. Vault provides a unified interface to any secret, while
|
|
|
|
providing tight access control and recording a detailed audit log.
|
|
|
|
|
2015-07-18 15:44:59 +08:00
|
|
|
## docker-compose.yml
|
|
|
|
|
|
|
|
```
|
|
|
|
vault:
|
|
|
|
image: vimagick/vault
|
|
|
|
ports:
|
|
|
|
- "8200:8200"
|
2015-07-18 16:24:47 +08:00
|
|
|
volumes:
|
|
|
|
- vault/vault.crt:/etc/vault/vault.crt
|
|
|
|
- vault/vault.key:/etc/vault/vault.key
|
2015-07-18 18:12:21 +08:00
|
|
|
cap_add:
|
|
|
|
- IPC_LOCK
|
2015-07-18 15:44:59 +08:00
|
|
|
restart: always
|
|
|
|
```
|
|
|
|
|
2015-07-18 16:32:56 +08:00
|
|
|
> Please distribute `vault.crt` to clients.
|
2015-07-18 16:24:47 +08:00
|
|
|
|
2015-07-18 15:44:59 +08:00
|
|
|
## server
|
|
|
|
|
|
|
|
```
|
|
|
|
$ cd ~/fig/vault
|
2015-07-18 16:24:47 +08:00
|
|
|
$ mkdir vault
|
|
|
|
$ openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout vault/vault.key -out vault/vault.crt
|
2015-07-18 15:44:59 +08:00
|
|
|
$ docker-compose up -d
|
|
|
|
$ docker cp vault_vault_1:/usr/bin/vault /usr/local/bin/
|
2015-07-18 17:08:30 +08:00
|
|
|
$ docker exec -it vault_vault_1 sh
|
|
|
|
>>> cd /etc/vault
|
|
|
|
>>> vault init -tls-skip-verify -key-shares=5 -key-threshold=3 | tee vault.secret
|
|
|
|
>>> exit
|
2015-07-18 17:46:59 +08:00
|
|
|
$ docker run --rm --volumes-from vault_vault_1 -v `pwd`:/backup alpine tar cvzf /backup/vault.tgz /etc/vault /var/lib/vault
|
2015-07-18 15:44:59 +08:00
|
|
|
```
|
|
|
|
|
2015-07-18 17:08:30 +08:00
|
|
|
> Split `vault.secret`, keep them a secret.
|
|
|
|
|
2015-07-18 15:44:59 +08:00
|
|
|
## client
|
|
|
|
|
|
|
|
```
|
2015-07-18 17:08:30 +08:00
|
|
|
$ export VAULT_ADDR='https://server:8200'
|
|
|
|
$ cp ~/fig/vault/vault/vault.crt /etc/ssl/certs/vault.pem
|
|
|
|
$ update-ca-certificates
|
2015-07-18 15:44:59 +08:00
|
|
|
$ vault status
|
2015-07-18 17:08:30 +08:00
|
|
|
$ vault unseal && vault unseal && vault unseal
|
2015-07-18 16:03:34 +08:00
|
|
|
$ vault auth
|
|
|
|
$ vault write secret/name key=value
|
|
|
|
$ vault read secret/name
|
2015-07-18 15:44:59 +08:00
|
|
|
$ vault seal
|
|
|
|
```
|
|
|
|
|
2015-07-18 15:30:30 +08:00
|
|
|
[1]: https://www.vaultproject.io/
|