Install certmanager and sshsignhost from RPM (#524)
certmanager and sshsignhost are now Go binaries released as RPMs, and their packaged paths collide with the venv install these helper classes manage. - Drop the pyvenv, pip, rendered script and /usr/local/bin symlink resources - Delete the now-unused Python script templates - Keep rendering /opt/<tool>/config.yaml, unchanged ownership and mode - Nest certmanager's output_path under vault:, where the binary reads it - Drop output_path from sshsignhost's config; the binary has no such key - Pin certmanager to 0.2.0 and sshsignhost to 0.1.0 on the puppet master role - Point sshsignhost at the sshca mount and signhost role, documented in doc/vault Reviewed-on: #524 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #524.
This commit is contained in:
+8
-31
@@ -88,36 +88,13 @@
|
||||
|
||||
# SSH Hostkey Signing
|
||||
|
||||
## create ssh engine, key, set ttl
|
||||
vault secrets enable -path=ssh-host-signer ssh
|
||||
vault write ssh-host-signer/config/ca generate_signing_key=true
|
||||
vault secrets tune -max-lease-ttl=87600h ssh-host-signer
|
||||
The `sshca` ssh engine, its `signhost` role, the `sshca/sign/signhost` policy and
|
||||
the `sshsigner` approle are managed in terraform-vault:
|
||||
|
||||
## create role
|
||||
vault write ssh-host-signer/roles/hostrole \
|
||||
key_type=ca \
|
||||
algorithm_signer=rsa-sha2-256 \
|
||||
ttl=87600h \
|
||||
allow_host_certificates=true \
|
||||
allowed_domains="unkin.net" \
|
||||
allow_subdomains=true \
|
||||
allow_baredomains=true
|
||||
- `config/ssh_secret_backend/sshca.yaml`
|
||||
- `config/ssh_secret_backend_role/sshca/signhost.yaml`
|
||||
- `config/auth_approle_role/approle/sshsigner.yaml`
|
||||
- `policies/sshca/sign/signhost.yaml`
|
||||
|
||||
## create policy to use hostrole
|
||||
cat <<EOF > sshsign-host.hcl
|
||||
path "ssh-host-signer/sign/hostrole" {
|
||||
capabilities = ["create", "update"]
|
||||
}
|
||||
EOF
|
||||
|
||||
vault policy write sshsign-host-policy sshsign-host.hcl
|
||||
|
||||
vault write auth/approle/role/sshsign-host-role \
|
||||
bind_secret_id=false \
|
||||
token_policies="sshsign-host-policy" \
|
||||
token_ttl=30s \
|
||||
token_max_ttl=30s \
|
||||
token_bound_cidrs="198.18.17.3/32,198.18.13.32/32,198.18.13.33/32,198.18.13.34/32"
|
||||
|
||||
## get the sshsign-host-role approle id
|
||||
vault read -field=role_id auth/approle/role/sshsign-host-role/role-id
|
||||
## get the sshsigner approle id
|
||||
vault read -field=role_id auth/approle/role/sshsigner/role-id
|
||||
|
||||
Reference in New Issue
Block a user