diff --git a/roles/vault/defaults/main.yml b/roles/vault/defaults/main.yml index acd2ac8fd..1f4a78b37 100644 --- a/roles/vault/defaults/main.yml +++ b/roles/vault/defaults/main.yml @@ -84,7 +84,7 @@ vault_ca_options: format: pem ttl: "{{ vault_max_lease_ttl }}" exclude_cn_from_sans: true - altnames: + alt_names: - "vault.{{ system_namespace }}.svc.{{ dns_domain }}" - "vault.{{ system_namespace }}.svc" - "vault.{{ system_namespace }}" diff --git a/roles/vault/tasks/bootstrap/gen_vault_certs.yml b/roles/vault/tasks/bootstrap/gen_vault_certs.yml index 8a82e5b6f..d542ef845 100644 --- a/roles/vault/tasks/bootstrap/gen_vault_certs.yml +++ b/roles/vault/tasks/bootstrap/gen_vault_certs.yml @@ -2,7 +2,7 @@ - include: ../shared/issue_cert.yml vars: issue_cert_common_name: "{{ vault_pki_mounts.vault.roles[0].name }}" - issue_cert_alt_names: "{{ groups.vault + ['localhost'] + vault_ca_options.vault.altnames|default() }}" + issue_cert_alt_names: "{{ groups.vault + ['localhost'] + vault_ca_options.vault.alt_names|default() }}" issue_cert_hosts: "{{ groups.vault }}" issue_cert_ip_sans: >- [