This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
|
hashicorp_vault [2026/02/25 16:16] val [KV secrets engine] |
hashicorp_vault [2026/03/02 14:20] (current) val [KV secrets engine] |
||
|---|---|---|---|
| Line 56: | Line 56: | ||
| ... | ... | ||
| + | UI CLI> vault kv-get secret/ansible/openvpn1 | ||
| + | |||
| + | / # ###vault kv get -version=3 secret/ansible/openvpn1 | ||
| / # ###vault kv delete secret/ansible/openvpn1 | / # ###vault kv delete secret/ansible/openvpn1 | ||
| Line 84: | Line 87: | ||
| </code> | </code> | ||
| ===== Vault policy ===== | ===== Vault policy ===== | ||
| + | |||
| + | * [[http://server.corpX.un:8200]] | ||
| + | |||
| <code> | <code> | ||
| / # vault policy write ansible-openvpn1 - <<EOF | / # vault policy write ansible-openvpn1 - <<EOF | ||
| Line 124: | Line 130: | ||
| ===== Vault token ===== | ===== Vault token ===== | ||
| <code> | <code> | ||
| - | / # vault token create -policy="ansible-openvpn1" | + | / # vault token create -policy="ansible-openvpn1" #-ttl=32d |
| Key Value | Key Value | ||
| --- ----- | --- ----- | ||
| Line 164: | Line 170: | ||
| server|gate# VAULT_ADDR='http://server.corpX.un:8200' | server|gate# VAULT_ADDR='http://server.corpX.un:8200' | ||
| server|gate# VAULT_TOKEN=hKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKk | server|gate# VAULT_TOKEN=hKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKk | ||
| - | server|gate# export VAULT_TOKEN=hKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKk | ||
| / # vault write auth/token/roles/ansible-openvpn1-role allowed_policies=ansible-openvpn1 bound_cidrs="192.168.X.0/24" | / # vault write auth/token/roles/ansible-openvpn1-role allowed_policies=ansible-openvpn1 bound_cidrs="192.168.X.0/24" | ||