Skip to content

Integrating MetalSoft with Hashicorp Vault

To integrate MetalSoft with Hashicorp Vault, follow these instructions if Vault was not enabled as part of the original installation.

Required permissions for MetalSoft vault user are:

path "metalsoft/*" {
capabilities = [ "create", "read", "update", "patch" ,"delete", "list" ]
}
path "auth/token/renew-self" {
capabilities = ["update"]
}
path "auth/token/lookup-self" {
capabilities = ["read"]
}
path "auth/token/revoke-self" {
capabilities = ["update"]
}

Apply default secret and configmap:

kubectl -n $ns apply -f scripts/vault-secrets.yaml

Once Vault is unsealed, run ./scripts/vault_start_agent.sh, which will:

  • enable Vault approle
  • overwrite vault-metalsoft-policy.hcl with capabilities for specific paths
  • apply policies for Metalsoft
  • set approle role_id and secret_id
  • update and apply vault-secrets.yaml
Terminal window
Usage:
scripts/vault_start_agent.sh <namespace> [path/to/vault-secrets.yaml]

After completing the above, update a few of the manifests to use the Vault agent:

# grep enable_vault *
auth-deployment.yaml: ### NOTE: enable_vault
auth-deployment.yaml: ### NOTE: enable_vault
auth-deployment.yaml: ### NOTE: enable_vault
configmaps.yaml: ### NOTE: enable_vault
inventory-deployment.yaml: ### NOTE: enable_vault
inventory-deployment.yaml: ### NOTE: enable_vault
inventory-deployment.yaml: ### NOTE: enable_vault
template-deployment.yaml: ### NOTE: enable_vault

Uncomment these sections and apply the YAML files to k8s.