UNCLASSIFIED - NO CUI

Skip to content
Snippets Groups Projects
Closed [P1BIGROCKS-2003] Add Hashicorp Vault into BigBang
  • View options
  • [P1BIGROCKS-2003] Add Hashicorp Vault into BigBang

  • View options
  • Closed Epic created by runyontr

    P1BIGROCKS-2003

    Vault Overview

    Conops

    Vault is planned to be used to provide these services

    Gitlab Pipelines

    As gitlab pipelines run, rather than providing credentials in gitlab for the pipeline to use, the gitlab jobs will load secrets from vault at startup time.

    • Twistlock
    • Anchore
    • Fortify
    • Sonarqube

    Air Gap KMS alternative

    • In airgap environments, KMS or cloud based encryption services may not be available for SOPS. This provides a consistent tool for encryption/decryption and key management

    Helm Chart

    Values used by CNAP here: https://repo1.dso.mil/platform-one/private/cnap/vault-deployment/-/blob/master/env/prod/patch-values.yaml#L28

    Iron Bank Images

    Acceptance Criteria

    • Deploy a healthy vault
      • @gabe.scarberry what other requirements do we need for base vault?
      • deploy with a HashiCorp "officially supported" storage backend
      • evaluate / document storage integration concerns with Big Bang
    • Document how to deploy vault safely (define)
      • how the root token will be used during initialization / initial configuration
      • how the root token will be revoked and the recovery process
    • Use Vault for SOPS encryption for Bigbang Deployment
    • Document how to provide Vault credentials to Flux for decrypting sops

    Phase 2 (after &116 (closed) )

    6 of 9 checklist items completed · Edited by Ryan Garcia

    Linked items 0

  • Link items together to show that they're related or that one is blocking others.

    Activity

    • All activity
    • Comments only
    • History only
    • Newest first
    • Oldest first
    Loading Loading Loading Loading Loading Loading Loading Loading Loading Loading