User Tools

Site Tools


hashicorp_vault

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
hashicorp_vault [2026/02/25 16:16]
val [KV secrets engine]
hashicorp_vault [2026/03/02 14:20] (current)
val [KV secrets engine]
Line 56: Line 56:
 ... ...
  
 +UI CLI> vault kv-get secret/​ansible/​openvpn1
 +
 +/ # ###vault kv get -version=3 secret/​ansible/​openvpn1
  
 / # ###vault kv delete secret/​ansible/​openvpn1 / # ###vault kv delete secret/​ansible/​openvpn1
Line 84: Line 87:
 </​code>​ </​code>​
 ===== Vault policy ===== ===== Vault policy =====
 +
 +  * [[http://​server.corpX.un:​8200]]
 +
 <​code>​ <​code>​
 / # vault policy write ansible-openvpn1 - <<EOF / # vault policy write ansible-openvpn1 - <<EOF
Line 124: Line 130:
 ===== Vault token ===== ===== Vault token =====
 <​code>​ <​code>​
-/ # vault token create -policy="​ansible-openvpn1"​+/ # vault token create -policy="​ansible-openvpn1" ​#-ttl=32d
 Key                  Value Key                  Value
 ---                  ----- ---                  -----
Line 164: Line 170:
 server|gate#​ VAULT_ADDR='​http://​server.corpX.un:​8200'​ server|gate#​ VAULT_ADDR='​http://​server.corpX.un:​8200'​
 server|gate# ​ VAULT_TOKEN=hKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKk server|gate# ​ VAULT_TOKEN=hKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKk
-server|gate# ​ export VAULT_TOKEN=hKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKk 
  
 / # vault write auth/​token/​roles/​ansible-openvpn1-role allowed_policies=ansible-openvpn1 bound_cidrs="​192.168.X.0/​24"​ / # vault write auth/​token/​roles/​ansible-openvpn1-role allowed_policies=ansible-openvpn1 bound_cidrs="​192.168.X.0/​24"​
hashicorp_vault.1772025385.txt.gz · Last modified: 2026/02/25 16:16 by val