fe51aa07be
profiles::pki::vault and profiles::ssh::sign shell out to /usr/local/bin/certmanager and /usr/local/bin/sshsignhost from generate() during catalog compilation. Neither binary exists in the compiler image, so every node using them fails to compile. - install certmanager v0.2.0 and sshsignhost v0.1.0 onto the shared bin volume with sha256 verification - wrap both at /usr/local/bin from a pre-default entrypoint hook, failing startup loudly if either is missing - mount read-only Vault configs for both: kubernetes auth on k8s/au/syd1, internal CA verified rather than skipped Reviewed-on: #482 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
12 lines
280 B
YAML
12 lines
280 B
YAML
---
|
|
vault:
|
|
addr: https://vault.service.consul:8200
|
|
auth_method: kubernetes
|
|
k8s_mount: k8s/au/syd1
|
|
k8s_role: puppet_sshsigner
|
|
jwt_path: /var/run/secrets/kubernetes.io/serviceaccount/token
|
|
mount_point: sshca
|
|
role_name: signhost
|
|
tls_skip_verify: false
|
|
timeout: 30s
|