Give the puppetserver compilers the Vault cert helpers (#482)
profiles::pki::vault and profiles::ssh::sign shell out to /usr/local/bin/certmanager and /usr/local/bin/sshsignhost from generate() during catalog compilation. Neither binary exists in the compiler image, so every node using them fails to compile. - install certmanager v0.2.0 and sshsignhost v0.1.0 onto the shared bin volume with sha256 verification - wrap both at /usr/local/bin from a pre-default entrypoint hook, failing startup loudly if either is missing - mount read-only Vault configs for both: kubernetes auth on k8s/au/syd1, internal CA verified rather than skipped Reviewed-on: #482 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #482.
This commit is contained in:
@@ -0,0 +1,11 @@
|
||||
---
|
||||
vault:
|
||||
addr: https://vault.service.consul:8200
|
||||
auth_method: kubernetes
|
||||
k8s_mount: k8s/au/syd1
|
||||
k8s_role: puppet_sshsigner
|
||||
jwt_path: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||
mount_point: sshca
|
||||
role_name: signhost
|
||||
tls_skip_verify: false
|
||||
timeout: 30s
|
||||
Reference in New Issue
Block a user