Skip to content

Backport of NET-1721: Automatic ACL bootstrap with Vault secrets backend into release/1.1.x#1988

Merged
hc-github-team-consul-core merged 6 commits intorelease/1.1.xfrom
backport/pglass/NET-1721-vault-secrets-backend-boostrap/rightly-better-crow
Mar 6, 2023
Merged

Backport of NET-1721: Automatic ACL bootstrap with Vault secrets backend into release/1.1.x#1988
hc-github-team-consul-core merged 6 commits intorelease/1.1.xfrom
backport/pglass/NET-1721-vault-secrets-backend-boostrap/rightly-better-crow

Conversation

@hc-github-team-consul-core
Copy link
Copy Markdown
Collaborator

Backport

This PR is auto-generated from #1920 to be assessed for backporting due to the inclusion of the label backport/1.1.x.

The below text is copied from the body of the original PR.


Changes proposed in this PR:

This updates server-acl-init to support automatic ACL bootstrapping when using the Vault secrets backend.

In order to accomplish this, the server-acl-init job runs the Vault agent as a sidecar (in addition to running as an init container). If the bootstrap token is not found in Vault, then server-acl-init will proceed with ACL bootstrapping and write the token back to Vault.

Because server-acl-init writes to Vault via the Vault agent, server-acl-init doesn't have to worry specifying a Vault token or TLS config that it would normally need to talk to the Vault servers.

This adds the Vault SDK to the control-plane binary, which is +1 MB to the consul-k8s-control-plane binary size (74MB to 75MB).

Related to #1176

How I've tested this PR:

Acceptance tests

How I expect reviewers to test this PR:

👀

Checklist:

  • Tests added
  • CHANGELOG entry added

    HashiCorp engineers only, community PRs should not add a changelog entry.
    Entries should use present tense (e.g. Add support for...)


Overview of commits

@hc-github-team-consul-core hc-github-team-consul-core force-pushed the backport/pglass/NET-1721-vault-secrets-backend-boostrap/rightly-better-crow branch from 6252348 to 28e9149 Compare March 6, 2023 19:11
@hc-github-team-consul-core hc-github-team-consul-core merged commit 91db918 into release/1.1.x Mar 6, 2023
@hc-github-team-consul-core hc-github-team-consul-core deleted the backport/pglass/NET-1721-vault-secrets-backend-boostrap/rightly-better-crow branch March 6, 2023 19:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant