{"id":850,"date":"2025-03-02T16:49:37","date_gmt":"2025-03-02T14:49:37","guid":{"rendered":"https:\/\/olvas.dev\/?p=850"},"modified":"2025-05-17T23:36:29","modified_gmt":"2025-05-17T21:36:29","slug":"%d1%81%d0%b5%d0%ba%d1%80%d0%b5%d1%82%d1%8b-%d0%b2-kubernetes-hashicorp-vault-external-secrets-operator","status":"publish","type":"post","link":"https:\/\/olvas.dev\/?p=850","title":{"rendered":"\u0421\u0435\u043a\u0440\u0435\u0442\u044b \u0432 Kubernetes &#8212;  Hashicorp Vault + External Secrets Operator"},"content":{"rendered":"\n<p>Hashicorp Vault \u0443\u0436\u0435 \u0434\u043e\u0432\u043e\u043b\u044c\u043d\u043e\u0435 \u0432\u0440\u0435\u043c\u044f \u043d\u0430 \u0441\u043b\u0443\u0445\u0443 \u0438 \u0437\u0430\u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u043e\u0432\u0430\u043b \u043a\u0430\u043a \u043d\u0430\u0434\u0435\u0436\u043d\u0430\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u0430 \u0445\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0439 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438(\u0441\u0435\u043a\u0440\u0435\u0442\u043e\u0432): \u043f\u0430\u0440\u043e\u043b\u0438, ssh \u043a\u043b\u044e\u0447\u0438, api \u0442\u043e\u043a\u0435\u043d\u044b, \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432 \u0438 \u043f\u0440.<\/p>\n\n\n\n<p>Hashicorp Vault \u043f\u043e\u043c\u043e\u0436\u0435\u0442 \u0440\u0435\u0448\u0438\u0442\u044c \u0441\u0440\u0430\u0437\u0443 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0437\u0430\u0434\u0430\u0447:<\/p>\n\n\n\n<p>\u2022 \u0421\u043e\u0437\u0434\u0430\u0442\u044c \u0435\u0434\u0438\u043d\u0441\u0442\u0432\u0435\u043d\u043d\u043e\u0435 \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0435 \u0441\u0435\u043a\u0440\u0435\u0442\u043e\u0432;<br>\u2022 \u0417\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u043e\u0442 \u0443\u0442\u0435\u0447\u043a\u0438 \u0441\u0435\u043a\u0440\u0435\u0442\u043e\u0432;<br>\u2022 \u0421\u0434\u0435\u043b\u0430\u0442\u044c \u0440\u0430\u0431\u043e\u0442\u0443 \u0441 \u0441\u0435\u043a\u0440\u0435\u0442\u0430\u043c\u0438 \u0434\u043b\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0443\u0434\u043e\u0431\u043d\u043e\u0439.<\/p>\n\n\n\n<p>\u041d\u0430 \u0442\u0435\u043a\u0443\u0449\u0438\u0439 \u043c\u043e\u043c\u0435\u043d\u0442 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u0435\u0442 \u0434\u043e\u0432\u043e\u043b\u044c\u043d\u043e \u043c\u043d\u043e\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u0433\u0430\u0446\u0438\u0438 Hashicorp Vault \u0441 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u043c\u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c\u0438 CI\/CD, \u043e\u0431\u043b\u0430\u0447\u043d\u044b\u043c\u0438 \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u0430\u043c\u0438, \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c\u0438 \u043e\u0440\u043a\u0435\u0441\u0442\u0440\u0430\u0446\u0438\u0438\/\u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0438\u0437\u0430\u0446\u0438\u0438<\/p>\n\n\n\n<p>\u041c\u044b \u0432 \u0440\u0430\u0431\u043e\u0442\u0435 \u0430\u043a\u0442\u0438\u0432\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c kubernetes. \u041e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0437\u0430\u0434\u0430\u0447\u0435\u0439 \u0431\u044b\u043b\u043e \u043d\u0430\u0439\u0442\u0438 \u0440\u0435\u0448\u0435\u043d\u0438\u0435, \u0447\u0442\u043e\u0431\u044b \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043d\u0430 \u0432\u044b\u0445\u043e\u0434\u0435 \u0441\u0435\u043a\u0440\u0435\u0442 kubernetes.<br>\u041f\u0435\u0440\u0435\u043f\u0440\u043e\u0431\u043e\u0432\u0430\u0432 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0441\u043f\u043e\u0441\u043e\u0431\u043e\u0432 \u0434\u043e\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0441\u0435\u043a\u0440\u0435\u0442\u044b \u0432 kubernetes \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Hashicorp Vault, \u043c\u044b \u043e\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u043b\u0438\u0441\u044c \u043d\u0430&nbsp;<a href=\"https:\/\/external-secrets.io\/latest\/\" target=\"_blank\" rel=\"noreferrer noopener\">External Secrets Operator<\/a>.<\/p>\n\n\n\n<p>\u041f\u0440\u043e\u0431\u043e\u0432\u0430\u043b\u0438:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u0421\u0440\u0435\u0434\u0441\u0442\u0432\u0430\u043c\u0438 Hashicorp Vault. Vault Agent \u043c\u043e\u043d\u0442\u0438\u0440\u0443\u0435\u0442 \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e \u0441 \u0441\u0435\u043a\u0440\u0435\u0442\u0430\u043c\u0438 \u0447\u0435\u0440\u0435\u0437 init \u0438\u043b\u0438 sidecar \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u044b. \u041d\u0435 \u043f\u043e\u0434\u0445\u043e\u0434\u0438\u0442, \u0442.\u043a. \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u0430 \u043b\u0438\u0448\u043d\u044f\u044f \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0430 \u043d\u0430 \u043a\u043b\u0430\u0441\u0442\u0435\u0440 \u043f\u0440\u0438 \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u0438 \u043b\u0438\u0448\u043d\u0438\u0445 \u043f\u043e\u0434\u043e\u0432. \u041f\u043b\u044e\u0441 \u043d\u0435 \u0443\u043c\u0435\u044e\u0442 \u043f\u0440\u0435\u043e\u0431\u0440\u0430\u0437\u043e\u0432\u0430\u0442\u044c \u0441\u0435\u043a\u0440\u0435\u0442\u044b Vault \u0432 \u0441\u0435\u043a\u0440\u0435\u0442\u044b Kubernetes, \u0430 \u0441\u043e\u0445\u0440\u0430\u043d\u044f\u0435\u0442 \u0441\u0435\u043a\u0440\u0435\u0442\u044b \u0432 \u0444\u0430\u0439\u043b\u044b.<\/li>\n\n\n\n<li><a href=\"https:\/\/bank-vaults.dev\/\" target=\"_blank\" rel=\"noreferrer noopener\">Bank Vault<\/a>\u00a0\u041d\u0435 \u043f\u043e\u0434\u0445\u043e\u0434\u0438\u0442, \u0441\u043e\u0445\u0440\u0430\u043d\u044f\u0435\u0442 \u0441\u0435\u043a\u0440\u0435\u0442\u044b \u0432 \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0435 \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f.<\/li>\n\n\n\n<li><a href=\"https:\/\/argocd-vault-plugin.readthedocs.io\/en\/stable\/\" target=\"_blank\" rel=\"noreferrer noopener\">ArgoCD Vault Plugin<\/a>\u00a0\u0423\u043c\u0435\u0435\u0442 \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c \u0441 \u0441\u0435\u043a\u0440\u0435\u0442\u0430\u043c\u0438 kubernetes, \u043d\u043e \u043f\u043e\u043a\u0430\u0437\u0430\u043b\u0441\u044f \u0441\u043b\u043e\u0436\u043d\u044b\u043c \u0432 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0435.<\/li>\n<\/ul>\n\n\n\n<p>External Secrets Operator \u043f\u0440\u043e\u0441\u0442\u044b\u043c\u0438 \u0441\u043b\u043e\u0432\u0430\u043c\u0438 &#8212; \u044d\u0442\u043e \u043e\u043f\u0435\u0440\u0430\u0442\u043e\u0440 \u0434\u043b\u044f kubernetes, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0438 \u0441\u0438\u043d\u0445\u0440\u043e\u043d\u0438\u0437\u0438\u0440\u0443\u0435\u0442 \u0441\u0435\u043a\u0440\u0435\u0442\u044b \u0438\u0437 \u0432\u043d\u0435\u0448\u043d\u0438\u0445 API \u0438 \u0441\u043e\u0437\u0434\u0430\u0435\u0442 \u0438\u0445 \u0432 kubernetes. \u0415\u0441\u043b\u0438 \u0441\u0435\u043a\u0440\u0435\u0442 \u0432\u043e \u0432\u043d\u0435\u0448\u043d\u0435\u043c API \u0438\u0437\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f, \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440 \u043e\u0431\u043d\u043e\u0432\u043b\u044f\u0435\u0442 \u0441\u0435\u043a\u0440\u0435\u0442\u044b.<\/p>\n\n\n\n<p>\u0421 \u0442\u043e\u0447\u043a\u0438 \u0437\u0440\u0435\u043d\u0438\u044f \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 kubernetes \u0435\u0441\u0442\u044c \u043f\u0430\u0440\u0430 \u043c\u043e\u043c\u0435\u043d\u0442\u043e\u0432:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u041d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c RBAC \u0432 kubernetes, \u0447\u0442\u043e\u0431\u044b \u0438\u0441\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u0434\u043e \u0440\u0435\u0441\u0443\u0440\u0441\u0430 secrets. \u0414\u043b\u044f \u0442\u043e\u0433\u043e, \u0447\u0442\u043e\u0431\u044b \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u043d\u0435 \u0441\u043c\u043e\u0433 \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0442\u044c \u0441\u0435\u043a\u0440\u0435\u0442.<\/li>\n\n\n\n<li>\u0415\u0441\u043b\u0438 \u0435\u0441\u0442\u044c \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u044c, \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0443. \u0415\u0441\u043b\u0438 \u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0435\u0441\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043f\u043e\u0434\u0443, \u043e\u043d \u0441\u043c\u043e\u0436\u0435\u0442 \u043f\u043e\u0441\u043c\u043e\u0442\u0440\u0435\u0442\u044c \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0435\/\u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 \u0441\u0435\u043a\u0440\u0435\u0442\u0430 \u0447\u0435\u0440\u0435\u0437 \u0442\u0435\u0440\u043c\u0438\u043d\u0430\u043b \u0438\u043b\u0438 \u043b\u043e\u0433\u0438 \u043f\u043e\u0434\u0430.<\/li>\n<\/ul>\n\n\n\n<p>\u0421\u043e \u0441\u0442\u043e\u0440\u043e\u043d\u044b Hashicorp Vault \u0432\u0441\u0435 \u0437\u0430\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u043e. \u0427\u0442\u043e\u0431\u044b \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a api, \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u0432\u043b\u0430\u0434\u0435\u0442\u044c \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u043c\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u044f\u043c\u0438 \u0434\u043b\u044f \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438.<br>\u041f\u043b\u044e\u0441 \u043f\u0440\u0438 \u0440\u0435\u0441\u0442\u0430\u0440\u0442\u0435 \u043a\u043b\u0430\u0441\u0442\u0435\u0440 \u0437\u0430\u043f\u0435\u0447\u0430\u0442\u044b\u0432\u0430\u0435\u0442\u0441\u044f, \u0435\u0441\u043b\u0438 \u043a\u043e\u043d\u0435\u0447\u043d\u043e \u043d\u0435 \u043d\u0430\u0441\u0442\u0440\u043e\u0435\u043d\u043e \u0430\u0432\u0442\u043e\u0440\u0430\u0441\u043f\u0435\u0447\u0430\u0442\u044b\u0432\u0430\u043d\u0438\u0435 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0430(autounseal) \u0442\u0440\u0430\u043d\u0437\u0438\u0442\u043d\u044b\u043c\u0438 \u043a\u043b\u044e\u0447\u0430\u043c\u0438. \u0414\u043b\u044f \u0440\u0443\u0447\u043d\u043e\u0433\u043e \u0440\u0430\u0441\u043f\u0435\u0447\u0430\u0442\u044b\u0432\u0430\u043d\u0438\u044f \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0442\u0440\u0435\u0431\u0443\u044e\u0442\u0441\u044f 3 \u0438\u0437 5 \u043a\u043b\u044e\u0447\u0435\u0439(unseal keys). \u0412 \u0438\u0434\u0435\u0430\u043b\u0435 \u043a\u043b\u044e\u0447\u0438 \u0434\u043e\u043b\u0436\u043d\u044b \u0445\u0440\u0430\u043d\u0438\u0442\u044c\u0441\u044f \u0443 \u0440\u0430\u0437\u043d\u044b\u0445 \u043b\u044e\u0434\u0435\u0439.<\/p>\n\n\n\n<p>\u0420\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f \u043f\u043e \u044d\u0442\u0430\u043f\u0430\u043c<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u0427\u0442\u043e \u043f\u043e\u0442\u0440\u0435\u0431\u0443\u0435\u0442\u0441\u044f \u0434\u043b\u044f \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438?<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u041a\u043b\u0430\u0441\u0442\u0435\u0440 kubernetes \u0432\u0435\u0440\u0441\u0438\u0438 \u043c\u0438\u043d\u0438\u043c\u0443\u043c 1.22+ \u0441\u043e\u0433\u043b\u0430\u0441\u043d\u043e \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u0430\u0446\u0438\u0438<\/li>\n\n\n\n<li>Helm \u0432\u0435\u0440\u0441\u0438\u0438 3.6+ \u0441\u043e\u0433\u043b\u0430\u0441\u043d\u043e \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u0430\u0446\u0438\u0438<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u042d\u0442\u0430\u043f 1<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 vault<\/h4>\n\n\n\n<p>\u0414\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u043c \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0439 hashicorp \u0438 \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u043c vault. \u0412 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0431\u0435\u043a\u0435\u043d\u0434\u0430 Integrated Storage (Raft).<\/p>\n\n\n\n<p>Integrated Storage (Raft) \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0442\u0430\u043a\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c, \u0447\u0442\u043e \u0432\u0441\u0435 \u0443\u0437\u043b\u044b \u0432 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0435 Vault \u0431\u0443\u0434\u0443\u0442 \u0438\u043c\u0435\u0442\u044c \u0440\u0435\u043f\u043b\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u0443\u044e \u043a\u043e\u043f\u0438\u044e \u0434\u0430\u043d\u043d\u044b\u0445 Vault. Integrated Storage Raft \u043e\u0444\u0438\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u0442\u0441\u044f Hashicorp.<\/p>\n\n\n\n<p>\u0411\u0435\u043a\u0430\u043f \u043c\u043e\u0436\u043d\u043e \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0442\u044c \u043d\u0430 \u043b\u044e\u0431\u043e\u043c \u0438\u0437 \u0443\u0437\u043b\u043e\u0432.<br>\u041a\u043e\u043c\u0430\u043d\u0434\u044b \u0434\u043e\u0432\u043e\u043b\u044c\u043d\u043e \u043f\u0440\u043e\u0441\u0442\u044b\u0435:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>vault operator raft snapshot save new.snapshot<\/li>\n\n\n\n<li>vault operator raft snapshot restore new.snapshot<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>helm repo add hashicorp https:\/\/helm.releases.hashicorp.com\n\nhelm install vault hashicorp\/vault \\\n  --set='server.ha.enabled=true' \\\n  --set='server.ha.raft.enabled=true' \\\n  -n vault \\\n  --create-namespace \n<\/code><\/pre>\n\n\n\n<p>\u041f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c, \u0447\u0442\u043e \u0432\u0441\u0435 \u043f\u043e\u0434\u044b \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u043b\u0438\u0441\u044c:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>kubectl get po -n vault\n\nNAME                                               READY   STATUS    RESTARTS   AGE\nvault-0                                             1\/1     Running   0          1d\nvault-1                                             1\/1     Running   0          1d\nvault-2                                             1\/1     Running   0          1d\n<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">2. \u0418\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f \u0438 \u0440\u0430\u0441\u043f\u0435\u0447\u0430\u0442\u044b\u0432\u0430\u043d\u0438\u0435 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0430 Hashicorp Vault<\/h4>\n\n\n\n<p>\u0418\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0438\u0440\u0443\u0435\u043c vault<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>kubectl exec -ti vault-0 -- vault operator init\n<\/code><\/pre>\n\n\n\n<p>\u041f\u043e\u0441\u043b\u0435 \u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 vault \u043f\u043e\u043b\u0443\u0447\u0438\u043c \u043a\u043e\u0440\u043d\u0435\u0432\u043e\u0439 \u043a\u043b\u044e\u0447 \u0438 5 \u043a\u043b\u044e\u0447\u0435\u0439 \u0434\u043b\u044f \u0440\u0430\u0441\u043f\u0435\u0447\u0430\u0442\u043a\u0438.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Unseal Key 1: wQRU1yjL88Plb3rPSQPUfLw1KOCsPMACpXLY0Ixbdhfg\nUnseal Key 2: ai3NajyVDFyqG5Lz6pDYNX118ti9Slqo2vueQhtg6Usq\nUnseal Key 3: x1a0VneA8cBkcXMDkxPwOOByPzlwuUw3dNaa7hfUqDAx\nUnseal Key 4: oztkcLGBAesVQwyO7Kc059xlqq9YSh1vkEkQFzKlnwae\nUnseal Key 5: 5cVmmDVZ7BIbQolCQdCoUXhdTRojPD2rgE1t83QgRKNn\n \nInitial Root Token: s.lTEYiTAv63CLsf0FqBcS672x                     \n<\/code><\/pre>\n\n\n\n<p>\u0420\u0430\u0441\u043f\u0435\u0447\u0430\u0442\u0430\u0435\u043c \u043a\u043b\u0430\u0441\u0442\u0435\u0440. \u041f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0442\u0441\u044f 3 unseal \u043a\u043b\u044e\u0447\u0430.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>kubectl exec -ti vault-0 -- vault operator unseal\n<\/code><\/pre>\n\n\n\n<p>\u041f\u043e\u0441\u043b\u0435 \u043f\u0440\u0438\u0441\u043e\u0435\u0434\u0438\u043d\u0438\u043c \u043e\u0441\u0442\u0430\u0432\u0448\u0438\u0435\u0441\u044f 2 \u043f\u043e\u0434\u0430 \u043a \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0443.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>kubectl exec -ti vault-1 -- vault operator raft join http:\/\/vault-0.vault-internal:8200\nkubectl exec -ti vault-1 -- vault operator unseal\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>kubectl exec -ti vault-2 -- vault operator raft join http:\/\/vault-0.vault-internal:8200\nkubectl exec -ti vault-2 -- vault operator unseal\n<\/code><\/pre>\n\n\n\n<p>\u041f\u043e\u0441\u043b\u0435 \u0440\u0430\u0441\u043f\u0435\u0447\u0430\u0442\u043a\u0438 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0430 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0438\u0440\u0443\u0435\u043c\u0441\u044f \u0432 vault \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043a\u043e\u0440\u043d\u0435\u0432\u043e\u0439 \u043a\u043b\u044e\u0447(Initial Root Token).<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>kubectl exec -ti vault-0 -- vault login\n<\/code><\/pre>\n\n\n\n<p>\u041f\u0440\u043e\u0432\u0435\u0440\u0438\u043c \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0430<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>kubectl exec -ti vault-0 -- vault operator raft list-peers\n\nNode                                    Address                        State       Voter\n----                                    -------                        -----       -----\n4rzii8af-8847-7f28-23f0-p36vwkghqxng    vault-0.vault-internal:8201    leader      true\naydfyon3-6b3x-1b7x-9b34-bdzpa1el2dzf    vault-1.vault-internal:8201     follower   true\n2tjh4iqi-8bcv-8b2n-1b7s-wj6wtxgOk5cs     vault-2.vault-internal:8201    follower    true\n<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">3. \u0421\u043e\u0437\u0434\u0430\u043d\u0438\u0435 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0438 \u043d\u0430 \u0447\u0442\u0435\u043d\u0438\u0435 \u0441\u0435\u043a\u0440\u0435\u0442\u043e\u0432 \u0438\u0437 Hashicorp Vault<\/h4>\n\n\n\n<p>\u041c\u044b \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c \u0432\u0442\u043e\u0440\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e KV \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0430, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u043f\u0443\u0442\u044c \u0434\u043e \u0441\u0435\u043a\u0440\u0435\u0442\u0430 \u0431\u0443\u0434\u0435\u0442 \/projects\/data\/ \u0438 \/projects\/metadata.<\/p>\n\n\n\n<p>\u041e\u0434\u043d\u043e \u0438\u0437 \u043e\u0442\u043b\u0438\u0447\u0438\u0439 \u043c\u0435\u0436\u0434\u0443 \u0432\u0435\u0440\u0441\u0438\u044f\u043c\u0438, \u0447\u0442\u043e \u0432\u0442\u043e\u0440\u0430\u044f \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u0442 \u0432\u0435\u0440\u0441\u0438\u043e\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435.<\/p>\n\n\n\n<p>\u041f\u043b\u044e\u0441 \u0432\u044b\u0434\u0430\u0434\u0438\u043c \u043f\u0440\u0430\u0432\u0430 \u043d\u0430 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 \u0442\u043e\u043a\u0435\u043d\u0430.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>vault policy write read-secret - &lt;&lt;EOF\npath \"\/projects\/data\/dev\/*\" {\n    capabilities = &#91;\"read\", \"list\"]\n}\n\npath \"\/projects\/metadata\/dev\/*\" {\n    capabilities = &#91;\"read\", \"list\"]\n}\n\npath \"auth\/token\/renew-self\" {\n    capabilities = &#91;\"update\"]\n}\nEOF\n<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">4. \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 kubernetes<\/h4>\n\n\n\n<pre class=\"wp-block-code\"><code>vault auth enable kubernetes\n\nvault write auth\/kubernetes\/config \\\nkubernetes_host=https:\/\/${KUBERNETES_PORT_443_TCP_ADDR}:443 \\\nissuer=\"https:\/\/kubernetes.default.svc.cluster.local\"\n<\/code><\/pre>\n\n\n\n<p>\u0441\u043e\u0437\u0434\u0430\u0434\u0438\u043c \u0440\u043e\u043b\u044c<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>vault write auth\/kubernetes\/role\/read-secret \\\nbound_service_account_names=vault-auth \\\nbound_service_account_namespaces=vault \\\npolicies=read-secret \\\nalias_name_source=serviceaccount_name \\\nttl=1h\n<\/code><\/pre>\n\n\n\n<p>\u0441\u043e\u0437\u0434\u0430\u0434\u0438\u043c service account<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>kubectl create serviceaccount vault-auth -n vault\n<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">6. \u0421\u043e\u0437\u0434\u0430\u0434\u0438\u043c \u0441\u0435\u043a\u0440\u0435\u0442<\/h4>\n\n\n\n<pre class=\"wp-block-code\"><code>vault kv put projects\/dev\/app user=admin password=123456\n==== Secret Path ====\nprojects\/data\/dev-app\n\n======= Metadata =======\nKey                Value\n---                -----\ncreated_time       2023-08-18T10:28:38.163062633Z\ncustom_metadata    &lt;nil&gt;\ndeletion_time      n\/a\ndestroyed          false\nversion            1\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u042d\u0442\u0430\u043f 2<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 External Secrets Operator<\/h4>\n\n\n\n<pre class=\"wp-block-code\"><code>helm repo add external-secrets https:\/\/charts.external-secrets.io\n\nhelm install external-secrets \\\n   external-secrets\/external-secrets \\\n   -n vault \\\n   --create-namespace \n<\/code><\/pre>\n\n\n\n<p>\u041f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c, \u0447\u0442\u043e \u0432\u0441\u0435 \u043f\u043e\u0434\u044b \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u043b\u0438\u0441\u044c:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>kubectl get po -n vault\n\nNAME                                                READY   STATUS    RESTARTS   AGE\nexternal-secrets-h4ls02c0wd-1cxyr                   1\/1     Running   0          58d\nexternal-secrets-cert-controller-h4lfd8bfzg-km8ez   1\/1     Running   0          58d\nexternal-secrets-webhook-su3x3fOjk-uxsy2            1\/1     Running   0          58d\n<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">2. \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 External Secrets Operator<\/h4>\n\n\n\n<p>External Secrets Operator &#8212; \u043d\u0430\u0431\u043e\u0440 custom resources \u0442\u0430\u043a\u0438\u0445 \u043a\u0430\u043a: ExternalSecret, SecretStore \u0438 ClusterSecretStore.<\/p>\n\n\n\n<p>\u041c\u044b \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u0442\u043e\u043b\u044c\u043a\u043e ExternalSecret \u0438 SecretStore, \u0442.\u043a. \u0434\u043b\u044f \u043a\u0430\u0436\u0434\u043e\u0433\u043e \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0430 \u0438\u043c\u0435\u043d(namespace) \u0441\u0432\u043e\u0438 \u0441\u0435\u043a\u0440\u0435\u0442\u044b. ClusterSecretStore \u0431\u0443\u0434\u0435\u0442 \u0434\u043e\u0441\u0442\u0443\u043f\u0435\u043d \u0438\u0437 \u043b\u044e\u0431\u043e\u0433\u043e \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0430 \u0438\u043c\u0435\u043d(namespace).<\/p>\n\n\n\n<p>SecretStore \u0443\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442 \u043a\u0430\u043a \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f.<\/p>\n\n\n\n<p>ExternalSecret \u0443\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442 \u043a\u0430\u043a\u0438\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u043d\u0443\u0436\u043d\u043e \u0438\u0437\u0432\u043b\u0435\u0447\u044c.<\/p>\n\n\n\n<p>\u0421\u043e\u0437\u0434\u0430\u0434\u0438\u043c \u043c\u0430\u043d\u0438\u0444\u0435\u0441\u0442\u044b:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>apiVersion: external-secrets.io\/v1beta1\nkind: SecretStore\nmetadata:\n  name: app\n  namespace: dev-app\nspec:\n  provider:\n    vault:\n      server: \"http:\/\/vault.vault:8200\" # \u0430\u0434\u0440\u0435\u0441 \u043d\u0430\u0448\u0435\u0433\u043e vault. \u0421\u043a\u043b\u0430\u0434\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u0438\u0437 \u0438\u043c\u0435\u043d\u0438 \u0441\u0435\u0440\u0432\u0438\u0441\u0430 \u0438 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0430 \u0438\u043c\u0435\u043d.\n      path: \"projects\" # \u0438\u043c\u044f kv\n      version: \"v2\" # \u0432\u0435\u0440\u0441\u0438\u044f kv\n      auth:\n        kubernetes: # \u043c\u0435\u0442\u043e\u0434 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438\n          mountPath: \"kubernetes\"\n          role: \"read-secret\" # \u0440\u043e\u043b\u044c \u0434\u043b\u044f \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438\n          serviceAccountRef:\n            name: \"vault-auth\" # \u0438\u043c\u044f \u043d\u0430\u0448\u0435\u0433\u043e serviceAccount\n---\napiVersion: external-secrets.io\/v1beta1\nkind: ExternalSecret\nmetadata:\n  name: app\n  namespace: dev-app\nspec:\n  refreshInterval: \"15s\"\n  secretStoreRef:\n    name: app # \u0438\u043c\u044f SecretStore\n    kind: SecretStore\n  target:\n    name: vault-secrets # \u0438\u043c\u044f \u0431\u0443\u0434\u0443\u0449\u0435\u0433\u043e \u0441\u0435\u043a\u0440\u0435\u0442\u0430 kubernetes\n  data:\n    - secretKey: user # \u043a\u043b\u044e\u0447 \u0441\u0435\u043a\u0440\u0435\u0442\u0430\n      remoteRef:\n        key: dev\/app # \u043f\u0443\u0442\u044c \u0434\u043e \u0441\u0435\u043a\u0440\u0435\u0442\u0430 \u0432 vault\n        property: user # \u043a\u043b\u044e\u0447 \u0441\u0435\u043a\u0440\u0435\u0442\u0430 \u0432 vault\n    - secretKey: password\n      remoteRef:\n        key: dev\/app\n        property: password\n<\/code><\/pre>\n\n\n\n<p>\u041f\u0440\u043e\u0432\u0435\u0440\u0438\u043c, \u0447\u0442\u043e \u0432\u0441\u0435 \u0441\u043e\u0437\u0434\u0430\u043b\u043e\u0441\u044c<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>kubectl get externalsecrets -n vault\nNAME                                  AGE   STATUS   CAPABILITIES   READY\nsecretstore.external-secrets.io\/app   14m   Valid    ReadWrite      True\n\nNAME                                     STORE   REFRESH INTERVAL   STATUS         READY\nexternalsecret.external-secrets.io\/app   app     15s                SecretSynced   True\n<\/code><\/pre>\n\n\n\n<p>\u041f\u0440\u043e\u0432\u0435\u0440\u0438\u043c \u043d\u0430\u0448 \u0441\u043e\u0437\u0434\u0430\u043d\u043d\u044b\u0439 \u0441\u0435\u043a\u0440\u0435\u0442<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>kubectl describe secrets -n vault vault-secrets\nName:         vault-secrets\nNamespace:    vault\nLabels:       &lt;none&gt;\nAnnotations:  created-by: system:serviceaccount:vault:external-secrets\n              reconcile.external-secrets.io\/data-hash: b749f0dfb88266e3b81d63dbc2a4402b\n\nType:  Opaque\n\nData\n====\npassword:  6 bytes\nuser:      5 bytes\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>kubectl get secrets\/vault-secrets --template={{.data.user}} | base64 -D\nadmin\nkubectl get secrets\/vault-secrets --template={{.data.password}} | base64 -D\n123456\n<\/code><\/pre>\n\n\n\n<p>\u041f\u043e\u0434\u0432\u0435\u0434\u0435\u043c \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u0438\u0442\u043e\u0433. \u042d\u0442\u043e\u0442 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442 \u0445\u043e\u0440\u043e\u0448\u043e \u0440\u0435\u0448\u0430\u0435\u0442 \u0437\u0430\u0434\u0430\u0447\u0443 \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0441\u0438\u043d\u0445\u0440\u043e\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u0435\u043a\u0440\u0435\u0442\u043e\u0432 \u043c\u0435\u0436\u0434\u0443 Vault \u0438 kubernetes. \u0422\u0430\u043a\u0436\u0435 ESO \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u0442 \u0434\u0440\u0443\u0433\u0438\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0441\u0435\u043a\u0440\u0435\u0442\u0430\u043c\u0438, \u0442\u0430\u043a\u0438\u0435 \u043a\u0430\u043a AWS Secrets Manager, GCP Secrets Manager, Yandex Lockbox, \u0447\u0442\u043e \u0443\u043f\u0440\u043e\u0449\u0430\u0435\u0442 \u0440\u0430\u0431\u043e\u0442\u0443.<\/p>\n\n\n\n<p>Copyright: <a href=\"https:\/\/habr.com\/ru\" target=\"_blank\" rel=\"noreferrer noopener\">habr.com<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hashicorp Vault \u0443\u0436\u0435 \u0434\u043e\u0432\u043e\u043b\u044c\u043d\u043e\u0435 \u0432\u0440\u0435\u043c\u044f \u043d\u0430 \u0441\u043b\u0443\u0445\u0443 \u0438 \u0437\u0430\u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u043e\u0432\u0430\u043b \u043a\u0430\u043a \u043d\u0430\u0434\u0435\u0436\u043d\u0430\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u0430 \u0445\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0439 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438(\u0441\u0435\u043a\u0440\u0435\u0442\u043e\u0432): \u043f\u0430\u0440\u043e\u043b\u0438, ssh \u043a\u043b\u044e\u0447\u0438, api \u0442\u043e\u043a\u0435\u043d\u044b, \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432 \u0438 \u043f\u0440. Hashicorp Vault \u043f\u043e\u043c\u043e\u0436\u0435\u0442 \u0440\u0435\u0448\u0438\u0442\u044c \u0441\u0440\u0430\u0437\u0443 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0437\u0430\u0434\u0430\u0447: \u2022 \u0421\u043e\u0437\u0434\u0430\u0442\u044c \u0435\u0434\u0438\u043d\u0441\u0442\u0432\u0435\u043d\u043d\u043e\u0435 \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0435 \u0441\u0435\u043a\u0440\u0435\u0442\u043e\u0432;\u2022 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":851,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[55,145,192,31,30,146,191,144],"class_list":["post-850","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-likbez","tag-devops","tag-hashicorp","tag-hashicorp-vault","tag-k8s","tag-kubernetes","tag-secrets","tag-secrets-management","tag-vault","entry-card--wide"],"_links":{"self":[{"href":"https:\/\/olvas.dev\/index.php?rest_route=\/wp\/v2\/posts\/850","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/olvas.dev\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/olvas.dev\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/olvas.dev\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/olvas.dev\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=850"}],"version-history":[{"count":1,"href":"https:\/\/olvas.dev\/index.php?rest_route=\/wp\/v2\/posts\/850\/revisions"}],"predecessor-version":[{"id":852,"href":"https:\/\/olvas.dev\/index.php?rest_route=\/wp\/v2\/posts\/850\/revisions\/852"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/olvas.dev\/index.php?rest_route=\/wp\/v2\/media\/851"}],"wp:attachment":[{"href":"https:\/\/olvas.dev\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=850"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/olvas.dev\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=850"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/olvas.dev\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=850"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}