feat: vault agent enablement on OfBorg #162

Merged
raito merged 10 commits from infra-automatic-pki into main 2025-01-02 17:40:14 +00:00
Owner

This brings our server of secrets closer to the machine safely, e.g. reusing systemd facilities and OpenBao system-wide authentication.

First usecase is OfBorg RabbitMQ mTLS certificates.

TODO:

  • make the lease and token not expire instantly
This brings our server of secrets closer to the machine safely, e.g. reusing systemd facilities and OpenBao system-wide authentication. First usecase is OfBorg RabbitMQ mTLS certificates. TODO: - [x] make the lease and token not expire instantly
raito added 2 commits 2025-01-01 01:21:55 +00:00
We remove one CA to send to all systems (infra CA).

Signed-off-by: Raito Bezarius <masterancpp@gmail.com>
This brings the openbao agent, a Go proxy to make the link between
systemd's LoadCredential and the openbao agent.

All that remains is to configure authentication on every system we need
to use OpenBao and then the templates for every secret we care about.

Signed-off-by: Raito Bezarius <masterancpp@gmail.com>
raito changed title from feat: vault agent enablement to WIP: feat: vault agent enablement 2025-01-01 01:22:00 +00:00
raito force-pushed infra-automatic-pki from 517774270e to 6ba24ad1cb 2025-01-01 02:43:33 +00:00 Compare
raito force-pushed infra-automatic-pki from 6ba24ad1cb to 1f634346eb 2025-01-01 02:50:34 +00:00 Compare
raito force-pushed infra-automatic-pki from 1f634346eb to 0b190209dd 2025-01-01 04:16:24 +00:00 Compare
raito force-pushed infra-automatic-pki from 0b190209dd to 6466155768 2025-01-02 17:24:38 +00:00 Compare
raito changed title from WIP: feat: vault agent enablement to feat: vault agent enablement 2025-01-02 17:24:59 +00:00
raito changed title from feat: vault agent enablement to feat: vault agent enablement on OfBorg 2025-01-02 17:25:05 +00:00
raito force-pushed infra-automatic-pki from 6466155768 to fb8eea1057 2025-01-02 17:39:57 +00:00 Compare
raito merged commit fb8eea1057 into main 2025-01-02 17:40:14 +00:00
raito deleted branch infra-automatic-pki 2025-01-02 17:40:15 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: the-distro/infra#162
No description provided.