Addition of experimental secrets-bridge (#140)
This is the basic service that enables bootstrapping keys to talk with Vault.
This commit is contained in:
@@ -0,0 +1,55 @@
|
||||
## Secrets Bridge Server (Experimental)
|
||||
---
|
||||
###Status: Experimental POC (Read: Do NOT use for production)
|
||||
Only works with Hashicorp Vault server in dev mode currently.
|
||||
|
||||
---
|
||||
#### Description:
|
||||
This is the server side component for the Vault Secrets bridge with Rancher. This service should *NOT* be deployed in the same environment as user applications. It will have access to Vault, and compromising it will give the person access to *ALL* secrets available in that environment. It should instead be run in an environment reserved for the team operating Rancher.
|
||||
|
||||
The reason this uses a temporary Cubbyhole token to start the service is that ENV variables do show up in the Rancher API and Docker inspect commands.
|
||||
|
||||
#### Pre-reqs:
|
||||
|
||||
A Vault server in Dev mode.
|
||||
|
||||
Create Vault Policies and Roles for at least the Issuing token.
|
||||
Something like:
|
||||
|
||||
```
|
||||
vault policy-write grantor-Default ./policies/grantor-Default
|
||||
vault policy-write test1 ./policies/test1
|
||||
vault policy-write test2 ./policies/test2
|
||||
```
|
||||
|
||||
|
||||
```
|
||||
curl -s -X POST -H "X-Vault-Token: ${VAULT_TOKEN}" -d '{"allowed_policies": "default,grantor,test1,test2"}' http://vault/v1/auth/token/roles/grantor-Default
|
||||
```
|
||||
|
||||
#### Configure and Launch:
|
||||
1. Create a token to be used to issue new tokens in the environment. As part of the "meta" on the token add a field called `configPath` and set that equal to a path in the secrets folder in Vault. (like `/secrets/secrets-bridge/Default`)
|
||||
|
||||
|
||||
```
|
||||
curl -s -X POST -H "X-Vault-Token: $ROOT_TOKEN" ${VAULT_URL}/v1/auth/token/create/grantor-Default -d '{"policies": ["default", "grantor", "test1", "test2"], "ttl": "72h", "meta": {"configPath": "secret/secrets-bridge/Default"}}' | jq -r '.auth.client_token'
|
||||
```
|
||||
|
||||
|
||||
2. Create a temporary token with (2) uses.
|
||||
|
||||
```
|
||||
curl -s -H "X-Vault-Token: $ROOT_TOKEN" ${VAULT_URL}/v1/auth/token/create -d '{"policies": ["default"], "ttl": "15m", "num_uses": 2}'|jq -r '.auth.client_token'
|
||||
```
|
||||
|
||||
3. Use the temporary token to put the issuing token into the Vault cubbyhole.
|
||||
|
||||
```
|
||||
curl -X POST -H "X-Vault-Token: ${TEMP_TOKEN}" ${VAULT_URL}/v1/cubbyhole/Default -d "{\"permKey\": \"${PERM_TOKEN}\"}"
|
||||
```
|
||||
|
||||
4. Create Cattle API keys for the environment this server will be handling. (Would recommend 1 server per environment)
|
||||
|
||||
5. Launch this app with all of the configs.
|
||||
|
||||
|
||||
@@ -0,0 +1,18 @@
|
||||
secrets-bridge:
|
||||
image: rancher/secrets-bridge:v0.0.2
|
||||
environment:
|
||||
CATTLE_ACCESS_KEY: ${CATTLE_ACCESS_KEY}
|
||||
CATTLE_SECRET_KEY: ${CATTLE_SECRET_KEY}
|
||||
CATTLE_URL: ${CATTLE_URL}
|
||||
VAULT_TOKEN: ${VAULT_TOKEN}
|
||||
VAULT_CUBBYPATH: ${VAULT_CUBBYPATH}
|
||||
command:
|
||||
- server
|
||||
- --vault-url
|
||||
- ${VAULT_URL}
|
||||
- --rancher-url
|
||||
- $CATTLE_URL
|
||||
- --rancher-secret
|
||||
- ${CATTLE_SECRET_KEY}
|
||||
- --rancher-access
|
||||
- ${CATTLE_ACCESS_KEY}
|
||||
@@ -0,0 +1,36 @@
|
||||
.catalog:
|
||||
name: "Secrets Bridge Server"
|
||||
version: 0.0.1-rancher1
|
||||
description: |
|
||||
Server side secrets bridge between Rancher and Vault
|
||||
questions:
|
||||
- variable: CATTLE_URL
|
||||
type: string
|
||||
label: "Cattle URL"
|
||||
required: true
|
||||
description: "URL to the Cattle Project this service is managing"
|
||||
- variable: CATTLE_ACCESS_KEY
|
||||
type: string
|
||||
label: "Cattle Access Key"
|
||||
required: true
|
||||
description: "Cattle Access API Key"
|
||||
- variable: CATTLE_SECRET_KEY
|
||||
type: password
|
||||
label: "Cattle Secret Key"
|
||||
required: true
|
||||
description: "Cattle Secret API Key"
|
||||
- variable: VAULT_TOKEN
|
||||
type: password
|
||||
label: "Vault Temp Token"
|
||||
required: true
|
||||
description: "Temporary Token to Access Vault Cubbyhole"
|
||||
- variable: VAULT_URL
|
||||
type: string
|
||||
label: "URL to Vault server"
|
||||
required: true
|
||||
description: "URL to the Vault server"
|
||||
- variable: VAULT_CUBBYPATH
|
||||
type: string
|
||||
label: "Vault Cubbyhole Path"
|
||||
required: true
|
||||
description: "Path to get the permenant API key"
|
||||
Reference in New Issue
Block a user