#vault (2020-01)
Discussions related to Hashicorp Vault
2020-01-13
data:image/s3,"s3://crabby-images/67e68/67e683361c271c4e26e156c64a1a2d27db2b053d" alt="David avatar"
I’m a bit confused by the AWS auth backend. Am I allowed to authenticate to Vault via AWS sts credentials from my local machine, or do I need to be on an EC2 when I assume a role so the metadata endpoint is present?
Essentially, is it possible to eventually say something like this on my local terminal: aws-vault exec sandbox-role -- vault login --method aws
and then vault kv read ...
?
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Yes, you can totally use this on your local machine
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
(and it also works with the metadata endpoint, if you happen to be in EC2)
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
also, aws-vault
provides it’s own “mock” AWS metadata service if you use the --server
mode
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
We have some rough docs here on how we use it: https://docs.cloudposse.com/tools/aws-vault/
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
not sure if they will help you
data:image/s3,"s3://crabby-images/67e68/67e683361c271c4e26e156c64a1a2d27db2b053d" alt="David avatar"
That does help, thanks!
It looks like I can use https://www.terraform.io/docs/providers/vault/r/aws_auth_backend_role.html and do something like:
resource "vault_aws_auth_backend_role" "local_iam_user_role" {
role = "some_role_name"
auth_type = "iam"
bound_iam_principal_arns = ["arn:aws:iam::<account_id>:role/SomeRoleOnlyAdminsHaveAccessTo"]
token_policies = ["admin"]
}
and then use credentials from aws-vault for the the role SomeRoleOnlyAdminsHaveAccessTo
2020-01-30
data:image/s3,"s3://crabby-images/d57ee/d57eebe531f4429a88fb2ecaab878242015471d1" alt="Iiro Niinikoski avatar"
A very blondie question… Vault… I’d assume you always want to firewall it? It’s anyway your secrets-API…
data:image/s3,"s3://crabby-images/56511/565110c5baaf97fce995c805ec750f2d59d84cc8" alt="sarkis avatar"
I’d say strongly recommended unless some extremely special case
data:image/s3,"s3://crabby-images/d57ee/d57eebe531f4429a88fb2ecaab878242015471d1" alt="Iiro Niinikoski avatar"
:)
2020-01-31
data:image/s3,"s3://crabby-images/67e68/67e683361c271c4e26e156c64a1a2d27db2b053d" alt="David avatar"
How would one restart a vault server? Or otherwise, how could I apply new changes to the config hcl file?
data:image/s3,"s3://crabby-images/56511/565110c5baaf97fce995c805ec750f2d59d84cc8" alt="sarkis avatar"
For security reasons only some configs are updated with a SIGHUP
signal to vault proc, which will not restart it completely (and possibly seal vault if you do not have auto-unseal enabled): https://www.vaultproject.io/docs/configuration/
Some of the ones I know of are tls_cert_file
and tls_key_file
. Not sure about others ;(