19 lines
600 B
HCL
19 lines
600 B
HCL
resource "vault_approle_auth_backend_role" "sshsigner" {
|
|
role_name = "sshsigner"
|
|
bind_secret_id = false
|
|
token_policies = [
|
|
"ssh-host-signer/sshsigner",
|
|
"sshca_signhost"
|
|
]
|
|
token_ttl = 30
|
|
token_max_ttl = 30
|
|
token_bound_cidrs = [
|
|
"198.18.25.5/32", # ausyd1nxvm2052.main.unkin.net
|
|
"198.18.26.3/32", # ausyd1nxvm2053.main.unkin.net
|
|
"198.18.27.89/32", # ausyd1nxvm2054.main.unkin.net
|
|
"198.18.28.8/32", # ausyd1nxvm2055.main.unkin.net
|
|
"198.18.29.33/32", # ausyd1nxvm2056.main.unkin.net
|
|
"198.18.29.239/32", # ausyd1nxvm2097.main.unkin.net
|
|
]
|
|
}
|