Merge pull request #2923 from bradbeam/vaultrkt

Adding uuidfile for rkt based vault to properly cleanup after itself
This commit is contained in:
Andreas Krüger 2018-06-27 11:18:39 +02:00 committed by GitHub
commit e24f888bc4
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -12,6 +12,8 @@ LimitNOFILE=40000
# Container has the following internal mount points: # Container has the following internal mount points:
# /vault/file/ # File backend storage location # /vault/file/ # File backend storage location
# /vault/logs/ # Log files # /vault/logs/ # Log files
ExecStartPre=-/usr/bin/rkt rm --uuid-file=/var/run/vault.uuid
ExecStart=/usr/bin/rkt run \ ExecStart=/usr/bin/rkt run \
--insecure-options=image \ --insecure-options=image \
--volume hosts,kind=host,source=/etc/hosts,readOnly=true \ --volume hosts,kind=host,source=/etc/hosts,readOnly=true \
@ -29,9 +31,15 @@ ExecStart=/usr/bin/rkt run \
--volume=etcd-cert-dir,kind=host,source={{ etcd_cert_dir }} \ --volume=etcd-cert-dir,kind=host,source={{ etcd_cert_dir }} \
--mount=volume=etcd-cert-dir,target={{ etcd_cert_dir }} \ --mount=volume=etcd-cert-dir,target={{ etcd_cert_dir }} \
docker://{{ vault_image_repo }}:{{ vault_image_tag }} \ docker://{{ vault_image_repo }}:{{ vault_image_tag }} \
--name={{ vault_container_name }} --net=host \ --uuid-file-save=/var/run/vault.uuid \
--name={{ vault_container_name }} \
--net=host \
--caps-retain=CAP_IPC_LOCK \ --caps-retain=CAP_IPC_LOCK \
--exec vault -- server --config={{ vault_config_dir }}/config.json --exec vault -- \
server \
--config={{ vault_config_dir }}/config.json
ExecStop=-/usr/bin/rkt stop --uuid-file=/var/run/vault.uuid
[Install] [Install]
WantedBy=multi-user.target WantedBy=multi-user.target