vault.values.yaml 1.1 KB

12345678910111213141516171819202122232425262728293031323334353637
  1. injector:
  2. enabled: false
  3. server:
  4. extraEnvironmentVars:
  5. VAULT_CACERT: /etc/vault-config/vault-server-ca.pem
  6. VAULT_ADDR: https://127.0.0.1:8200
  7. volumeMounts:
  8. - name: tls-config
  9. mountPath: /etc/vault-config
  10. readOnly: true
  11. volumes:
  12. - name: tls-config
  13. secret:
  14. secretName: vault-tls-config
  15. dataStorage:
  16. enabled: false # have ephemeral data
  17. standalone:
  18. config: |
  19. ui = true
  20. listener "tcp" {
  21. address = "[::]:8200"
  22. cluster_address = "[::]:8201"
  23. tls_cert_file = "/etc/vault-config/server-cert.pem"
  24. tls_key_file = "/etc/vault-config/server-cert-key.pem"
  25. tls_client_ca_file = "/etc/vault-config/vault-client-ca.pem"
  26. }
  27. listener "tcp" {
  28. address = "[::]:8210"
  29. cluster_address = "[::]:8211"
  30. tls_cert_file = "/etc/vault-config/server-cert.pem"
  31. tls_key_file = "/etc/vault-config/server-cert-key.pem"
  32. tls_client_ca_file = "/etc/vault-config/vault-client-ca.pem"
  33. tls_require_and_verify_client_cert = true
  34. }
  35. storage "file" {
  36. path = "/vault/data"
  37. }