Day 17. Hashicorp Vault: Server configuration for production

Hashicorp Vault: Server configuration for production

刚开始建置PRD环境时,总会怕漏设定了甚麽,一段时间的经验累积後,总算有个样子了,纪录让想使用的人参考。

cluster_name = "vault-cluster"
ui = true
log_level = "debug"
log_format = "standard"
disable_clustering = false
api_addr      = "https://vault.abc.com:8200"
cluster_addr  = "http://10.x.x.x:8201"
default_lease_ttl = "24h"
max_lease_ttl = "768h"
disable_mlock = false
pid_file = "/vault/vault.pid"


listener "tcp" {
  address         = "10.x.x.x:8200"
  cluster_address    = "10.x.x.x:8201"
  tls_disable     = false
  tls_cert_file    = "/vault/ssl/vault-ca.cer"
  tls_key_file     = "/vault/ssl/vault-key.key"
  tls_client_ca_file = "/vault/ssl/vault-client-ca.cer"
  tls_disable_client_certs = true
  tls_require_and_verify_client_cert = false
}

storage "raft" {
  path = "/vault/data"
  node_id = "vault-node1"
}

service_registration "consul" {
  address         = "10.x.x.x:8500"
  service         = "vault"
  scheme          = "https"
  service_address = ""
  tls_ca_file   = "/vault/ssl/ca.cer"
  tls_cert_file = "/vault/ssl/cert.cer"
  tls_key_file  = "/vault/ssl/key.key"
  token           = "xxx-xxx-xxx-xxx"
}

telemetry {
  prometheus_retention_time = "30s"
  disable_hostname = true
}


<<:  成员 5 人:第一个员工,是紧急出现的不明生物

>>:  [Day2][笔记] React.js 常用 的 ES6 语法(1)

Rust-资料型别-布林值

Rust 为了表示真假值,使用关键字true和false 这样的关键字具有非数字类型的表达式称为布林...

Day7|【Git】提交档案至储存库 - git commit

复习一下上一篇提到 git 四个常使用的指令: git status : 查询目前目录的「状态」 g...

赌场线仙 - K棒与移动平均线的华尔滋

最近研究K棒,跟着某知名投顾分析师看盘後解析,「站上五日线买,跌破五日线卖,投信看十日」各种台词朗朗...

Test

test ...

Python - 在 Windows 10 上使用 PySpark 连接 Mysql 资料库参考笔记

Python - 在 Windows 10 上使用 PySpark 连接 Mysql 资料库参考笔记...