Documentation
¶
Overview ¶
Package config parses the plugin configuration from command-line flags.
Plugin specific behavior and Vault client settings are configured through flags (see BindFlags). The Vault client ignores VAULT_* environment variables so stray environment values cannot override the explicit plugin configuration.
All authentication secret material is referenced through file paths so that Kubernetes can rotate the backing Secrets without changing the plugin configuration. The files are read lazily at authentication time, never here.
Index ¶
Constants ¶
const ( // FlagSocketPath is the Unix domain socket path the KMS v2 gRPC server listens on. FlagSocketPath = "socket-path" // FlagVaultAddress is the Vault/OpenBao server address. FlagVaultAddress = "vault-address" // FlagVaultNamespace is the Vault/OpenBao namespace. FlagVaultNamespace = "vault-namespace" // FlagVaultCACert is the path to the CA certificate file used to verify the Vault/OpenBao server. FlagVaultCACert = "vault-ca-cert" // FlagTransitMount is the Vault Transit secrets engine mount path. FlagTransitMount = "vault-transit-mount" // FlagKeyName is the Vault Transit key used for encrypt and decrypt operations. FlagKeyName = "vault-key-name" // FlagAuthMethod selects the Vault auth method: token, approle, userpass, kubernetes or jwt. FlagAuthMethod = "vault-auth-method" // FlagAuthMount overrides the Vault auth mount path for approle, userpass, kubernetes or jwt. FlagAuthMount = "vault-auth-mount" // FlagTokenCheckInterval is how often the token manager checks the current Vault token. FlagTokenCheckInterval = "vault-token-check-interval" // FlagLoginTimeout bounds one token manager check cycle, including authentication. FlagLoginTimeout = "vault-login-timeout" // FlagTokenFile is the path to a file containing the Vault token for token auth. FlagTokenFile = "vault-token-file" // FlagAppRoleRoleIDFile is the path to a file containing the AppRole role ID. FlagAppRoleRoleIDFile = "vault-approle-role-id-file" // FlagAppRoleSecretIDFile is the path to a file containing the AppRole secret ID. FlagAppRoleSecretIDFile = "vault-approle-secret-id-file" // FlagUserpassUsernameFile is the path to a file containing the userpass username. FlagUserpassUsernameFile = "vault-userpass-username-file" // FlagUserpassPasswordFile is the path to a file containing the userpass password. FlagUserpassPasswordFile = "vault-userpass-password-file" // FlagKubernetesRole is the Vault Kubernetes auth role name (not a Kubernetes RBAC role). FlagKubernetesRole = "vault-kubernetes-role" // FlagKubernetesJWTFile is the path to a file containing the service account JWT. FlagKubernetesJWTFile = "vault-kubernetes-jwt-file" // FlagJWTRole is the Vault JWT auth role name. FlagJWTRole = "vault-jwt-role" // FlagJWTFile is the path to a file containing the JWT presented to Vault for JWT auth. FlagJWTFile = "vault-jwt-file" )
Flag names accepted by the plugin.
const ( // DefaultTokenCheckInterval is how often the token manager checks the current Vault token. DefaultTokenCheckInterval = 60 * time.Second // DefaultLoginTimeout bounds one token manager check cycle, including authentication. DefaultLoginTimeout = 45 * time.Second )
const ( // DefaultSocketDir is the host path directory in which the Vault KMS plugin DaemonSet serves // its KMS v2 Unix domain socket. The kube-apiserver of encrypted Kamaji clusters mounts this // directory so it can reach the socket served on the same node. DefaultSocketDir = "/var/lib/dpf/kmsplugin/vault-kms" // DefaultSocketFile is the KMS v2 Unix domain socket served by the Vault KMS plugin DaemonSet. DefaultSocketFile = DefaultSocketDir + "/kms.sock" )
const DefaultTransitMount = "transit"
DefaultTransitMount is the default value for the transit mount flag.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type AuthMethod ¶
type AuthMethod string
AuthMethod enumerates the supported Vault auth methods.
const ( // AuthMethodToken authenticates using a Vault token read from a file. AuthMethodToken AuthMethod = "token" // AuthMethodAppRole authenticates using the AppRole auth method. AuthMethodAppRole AuthMethod = "approle" // AuthMethodUserpass authenticates using the userpass auth method. AuthMethodUserpass AuthMethod = "userpass" // AuthMethodKubernetes authenticates using the Kubernetes auth method. AuthMethodKubernetes AuthMethod = "kubernetes" // AuthMethodJWT authenticates using the JWT auth method. AuthMethodJWT AuthMethod = "jwt" )
type Config ¶
type Config struct {
// SocketPath is the Unix domain socket path served by the plugin.
SocketPath string
// VaultAddress is the Vault/OpenBao server address.
VaultAddress string
// VaultNamespace is the Vault/OpenBao namespace.
VaultNamespace string
// VaultCACertFile is the path to the CA certificate file used to verify the Vault/OpenBao server.
VaultCACertFile string
// TransitMount is the Vault Transit secrets engine mount path.
TransitMount string
// KeyName is the Vault Transit key name.
KeyName string
// AuthMethod selects how the plugin authenticates to Vault.
AuthMethod AuthMethod
// AuthMount optionally overrides the auth mount path for non-token methods.
AuthMount string
// TokenCheckInterval is how often the token manager checks the current Vault token.
TokenCheckInterval time.Duration
// LoginTimeout bounds one token manager check cycle, including authentication.
LoginTimeout time.Duration
// TokenFile is the path to the Vault token file (token auth).
TokenFile string
// AppRoleRoleIDFile is the path to the AppRole role ID file.
AppRoleRoleIDFile string
// AppRoleSecretIDFile is the path to the AppRole secret ID file.
AppRoleSecretIDFile string
// UserpassUsernameFile is the path to the userpass username file.
UserpassUsernameFile string
// UserpassPasswordFile is the path to the userpass password file.
UserpassPasswordFile string
// KubernetesRole is the Vault Kubernetes auth role name.
KubernetesRole string
// KubernetesJWTFile is the path to the service account JWT file.
KubernetesJWTFile string
// JWTRole is the Vault JWT auth role name.
JWTRole string
// JWTFile is the path to the file containing the JWT for JWT auth.
JWTFile string
}
Config holds the plugin specific configuration.
func BindFlags ¶
BindFlags registers the plugin flags on the given FlagSet and returns a Config whose fields are populated once the FlagSet is parsed by the caller. Call Validate after parsing.