updated the catalog for the secrets-bridge v1.2.0 release
This commit is contained in:
@@ -1,6 +1,7 @@
|
||||
.catalog:
|
||||
name: "Secrets Bridge Server"
|
||||
version: 0.0.1-rancher1
|
||||
maximum_rancher_version: v1.2.0-pre3
|
||||
description: |
|
||||
Server side secrets bridge between Rancher and Vault
|
||||
questions:
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
## Secrets Bridge Server (Beta)
|
||||
---
|
||||
#### Upgrade NOTICE
|
||||
|
||||
When upgrading this service keep in mind that if you use a new issuing token, tokens issued by the previous version will expire. This means running apps will no longer be able to access Vault using those tokens. If you need to keep those tokens fresh, then reuse the original PERM_TOKEN.
|
||||
|
||||
#### Description:
|
||||
This is the server side component for the Vault Secrets bridge with Rancher. This service should *NOT* be deployed in the same environment as user applications. It will have access to Vault, and compromising it will give the person access to *ALL* secrets available in that environment. It should instead be run in an environment reserved for the team operating Rancher.
|
||||
|
||||
The reason this uses a temporary Cubbyhole token to start the service is that ENV variables do show up in the Rancher API and Docker inspect commands. That said, if this service fails, the issuing token will expire and all app tokens will also expire.
|
||||
|
||||
#### Setup
|
||||
|
||||
See [setup guide](https://github.com/rancher/secrets-bridge/blob/master/docs/setup.md)
|
||||
|
||||
@@ -0,0 +1,24 @@
|
||||
secrets-bridge:
|
||||
image: rancher/secrets-bridge:v0.2.0
|
||||
environment:
|
||||
CATTLE_ACCESS_KEY: ${CATTLE_ACCESS_KEY}
|
||||
CATTLE_SECRET_KEY: ${CATTLE_SECRET_KEY}
|
||||
CATTLE_URL: ${CATTLE_URL}
|
||||
VAULT_TOKEN: ${VAULT_TOKEN}
|
||||
VAULT_CUBBYPATH: ${VAULT_CUBBYPATH}
|
||||
command:
|
||||
- server
|
||||
- --vault-url
|
||||
- ${VAULT_URL}
|
||||
- --rancher-url
|
||||
- $CATTLE_URL
|
||||
- --rancher-secret
|
||||
- ${CATTLE_SECRET_KEY}
|
||||
- --rancher-access
|
||||
- ${CATTLE_ACCESS_KEY}
|
||||
secrets-bridge-lb:
|
||||
ports:
|
||||
- "${LBPORT}:8181"
|
||||
image: rancher/load-balancer-service
|
||||
links:
|
||||
- secrets-bridge:secrets-bridge
|
||||
@@ -0,0 +1,52 @@
|
||||
.catalog:
|
||||
name: "Secrets Bridge Server"
|
||||
version: 0.1.0-rancher1
|
||||
minimum_rancher_version: v1.2.0
|
||||
description: |
|
||||
Server side secrets bridge between Rancher and Vault
|
||||
questions:
|
||||
- variable: CATTLE_URL
|
||||
type: string
|
||||
label: "Cattle URL"
|
||||
required: true
|
||||
description: "URL to the Cattle Project this service is managing"
|
||||
- variable: CATTLE_ACCESS_KEY
|
||||
type: string
|
||||
label: "Cattle Access Key"
|
||||
required: true
|
||||
description: "Cattle Access API Key"
|
||||
- variable: CATTLE_SECRET_KEY
|
||||
type: password
|
||||
label: "Cattle Secret Key"
|
||||
required: true
|
||||
description: "Cattle Secret API Key"
|
||||
- variable: VAULT_TOKEN
|
||||
type: password
|
||||
label: "Vault Temp Token"
|
||||
required: true
|
||||
description: "Temporary Token to Access Vault Cubbyhole"
|
||||
- variable: VAULT_URL
|
||||
type: string
|
||||
label: "URL to Vault server"
|
||||
required: true
|
||||
description: "URL to the Vault server"
|
||||
- variable: VAULT_CUBBYPATH
|
||||
type: string
|
||||
label: "Vault Cubbyhole Path"
|
||||
required: true
|
||||
description: "Path to get the permenant API key"
|
||||
- variable: LBPORT
|
||||
description: "Port for Secrets Bridge LB to listen on"
|
||||
label: "LB Port"
|
||||
type: string
|
||||
required: true
|
||||
secrets-bridge-lb:
|
||||
scale: 1
|
||||
load_balancer_config:
|
||||
haproxy_config: {}
|
||||
health_check:
|
||||
port: 42
|
||||
interval: 2000
|
||||
unhealthy_threshold: 3
|
||||
healthy_threshold: 2
|
||||
response_timeout: 2000
|
||||
@@ -1,4 +1,4 @@
|
||||
name: "Secrets Bridge"
|
||||
description: "Server side of bridge between Vault and Rancher"
|
||||
version: "0.0.1-rancher1"
|
||||
version: "0.1.0-rancher1"
|
||||
category: Security
|
||||
|
||||
Reference in New Issue
Block a user