5 Commits

Author SHA1 Message Date
a47fe24d51 update 2025-01-22 05:43:12 -06:00
881de48183 move back to HA 2025-01-22 05:42:15 -06:00
61eb2cb68e update 2025-01-22 05:41:34 -06:00
e17ffa9f3f update 2025-01-22 05:40:34 -06:00
b50e31d42d update 2025-01-22 05:39:28 -06:00
2 changed files with 10 additions and 8 deletions

View File

@@ -13,6 +13,6 @@ spec:
services:
- name: vault
port: 8200
scheme: http
scheme: https
tls:
secretName: vault-tls

View File

@@ -1,7 +1,7 @@
vault:
global:
enabled: true
tlsDisable: true
tlsDisable: false
resources:
requests:
memory: 256Mi
@@ -60,7 +60,7 @@ vault:
enabled: true
standalone:
enabled: true
enabled: false
config: |
disable_mlock = true
@@ -68,6 +68,8 @@ vault:
listener "tcp" {
address = "[::]:8200"
cluster_address = "[::]:8201"
tls_cert_file = "/vault/userconfig/vault-server-tls/vault.crt"
tls_key_file = "/vault/userconfig/vault-server-tls/vault.key"
}
seal "transit" {
@@ -84,10 +86,10 @@ vault:
# Run Vault in "HA" mode.
ha:
enabled: false
enabled: true
replicas: 3
raft:
enabled: false
enabled: true
setNodeId: true
config: |
@@ -111,19 +113,19 @@ vault:
storage "raft" {
path = "/vault/data"
retry_join {
leader_api_addr = "http://vault-0.vault-internal:8200"
leader_api_addr = "https://vault-0.vault-internal:8200"
leader_ca_cert_file = "/vault/userconfig/vault-server-tls/vault.ca"
leader_client_cert_file = "/vault/userconfig/vault-server-tls/vault.crt"
leader_client_key_file = "/vault/userconfig/vault-server-tls/vault.key"
}
retry_join {
leader_api_addr = "http://vault-1.vault-internal:8200"
leader_api_addr = "https://vault-1.vault-internal:8200"
leader_ca_cert_file = "/vault/userconfig/vault-server-tls/vault.ca"
leader_client_cert_file = "/vault/userconfig/vault-server-tls/vault.crt"
leader_client_key_file = "/vault/userconfig/vault-server-tls/vault.key"
}
retry_join {
leader_api_addr = "http://vault-2.vault-internal:8200"
leader_api_addr = "https://vault-2.vault-internal:8200"
leader_ca_cert_file = "/vault/userconfig/vault-server-tls/vault.ca"
leader_client_cert_file = "/vault/userconfig/vault-server-tls/vault.crt"
leader_client_key_file = "/vault/userconfig/vault-server-tls/vault.key"