Rotating the Gossip Encryption Key in HashiCorp Nomad

Поделиться
HTML-код
  • Опубликовано: 11 дек 2024

Комментарии • 4

  • @devhulk
    @devhulk Год назад

    Lets gooo!!!!

  • @AnthonyZboralski
    @AnthonyZboralski Год назад

    It would be nice to do the rotation automatically using Vault... Only wondering which ACL I need to list, add, remove and delete keys to generate a token for consult-template but couldn't find any docs.

    • @AnthonyZboralski
      @AnthonyZboralski Год назад

      If ACLs are enabled, this command requires a token with the agent:write capability.

    • @btkrausen
      @btkrausen  Год назад

      Vault doesn't support Gossip keys, unfortunately. You could probably use Vault to create a key and store it in the KV, but you'd still need some orchestrator to handle the rotation.