Compare commits
5 Commits
622114aace
...
a47fe24d51
| Author | SHA1 | Date | |
|---|---|---|---|
| a47fe24d51 | |||
| 881de48183 | |||
| 61eb2cb68e | |||
| e17ffa9f3f | |||
| b50e31d42d |
@@ -13,6 +13,6 @@ spec:
|
||||
services:
|
||||
- name: vault
|
||||
port: 8200
|
||||
scheme: http
|
||||
scheme: https
|
||||
tls:
|
||||
secretName: vault-tls
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
vault:
|
||||
global:
|
||||
enabled: true
|
||||
tlsDisable: true
|
||||
tlsDisable: false
|
||||
resources:
|
||||
requests:
|
||||
memory: 256Mi
|
||||
@@ -60,7 +60,7 @@ vault:
|
||||
enabled: true
|
||||
|
||||
standalone:
|
||||
enabled: true
|
||||
enabled: false
|
||||
|
||||
config: |
|
||||
disable_mlock = true
|
||||
@@ -68,6 +68,8 @@ vault:
|
||||
listener "tcp" {
|
||||
address = "[::]:8200"
|
||||
cluster_address = "[::]:8201"
|
||||
tls_cert_file = "/vault/userconfig/vault-server-tls/vault.crt"
|
||||
tls_key_file = "/vault/userconfig/vault-server-tls/vault.key"
|
||||
}
|
||||
|
||||
seal "transit" {
|
||||
@@ -84,10 +86,10 @@ vault:
|
||||
|
||||
# Run Vault in "HA" mode.
|
||||
ha:
|
||||
enabled: false
|
||||
enabled: true
|
||||
replicas: 3
|
||||
raft:
|
||||
enabled: false
|
||||
enabled: true
|
||||
setNodeId: true
|
||||
|
||||
config: |
|
||||
@@ -111,19 +113,19 @@ vault:
|
||||
storage "raft" {
|
||||
path = "/vault/data"
|
||||
retry_join {
|
||||
leader_api_addr = "http://vault-0.vault-internal:8200"
|
||||
leader_api_addr = "https://vault-0.vault-internal:8200"
|
||||
leader_ca_cert_file = "/vault/userconfig/vault-server-tls/vault.ca"
|
||||
leader_client_cert_file = "/vault/userconfig/vault-server-tls/vault.crt"
|
||||
leader_client_key_file = "/vault/userconfig/vault-server-tls/vault.key"
|
||||
}
|
||||
retry_join {
|
||||
leader_api_addr = "http://vault-1.vault-internal:8200"
|
||||
leader_api_addr = "https://vault-1.vault-internal:8200"
|
||||
leader_ca_cert_file = "/vault/userconfig/vault-server-tls/vault.ca"
|
||||
leader_client_cert_file = "/vault/userconfig/vault-server-tls/vault.crt"
|
||||
leader_client_key_file = "/vault/userconfig/vault-server-tls/vault.key"
|
||||
}
|
||||
retry_join {
|
||||
leader_api_addr = "http://vault-2.vault-internal:8200"
|
||||
leader_api_addr = "https://vault-2.vault-internal:8200"
|
||||
leader_ca_cert_file = "/vault/userconfig/vault-server-tls/vault.ca"
|
||||
leader_client_cert_file = "/vault/userconfig/vault-server-tls/vault.crt"
|
||||
leader_client_key_file = "/vault/userconfig/vault-server-tls/vault.key"
|
||||
|
||||
Reference in New Issue
Block a user