Vault should use cert auth for etcd

This commit is contained in:
Matthew Mosesohn 2018-01-31 20:26:19 +03:00
parent c1267004ef
commit 16629d0b8e

View file

@ -66,6 +66,8 @@ vault_config:
ha_enabled: "true" ha_enabled: "true"
redirect_addr: "https://{{ ansible_default_ipv4.address }}:{{ vault_port }}" redirect_addr: "https://{{ ansible_default_ipv4.address }}:{{ vault_port }}"
tls_ca_file: "{{ vault_etcd_cert_dir }}/ca.pem" tls_ca_file: "{{ vault_etcd_cert_dir }}/ca.pem"
tls_cert_file: "{{ vault_etcd_cert_dir}}/node-{{ inventory_hostname }}.pem"
tls_key_file: "{{ vault_etcd_cert_dir}}/node-{{ inventory_hostname }}-key.pem"
cluster_name: "kubernetes-vault" cluster_name: "kubernetes-vault"
default_lease_ttl: "{{ vault_default_lease_ttl }}" default_lease_ttl: "{{ vault_default_lease_ttl }}"
max_lease_ttl: "{{ vault_max_lease_ttl }}" max_lease_ttl: "{{ vault_max_lease_ttl }}"