diff --git a/data/helpers/init.sh b/data/helpers/init.sh index 2928481..c6397c0 100644 --- a/data/helpers/init.sh +++ b/data/helpers/init.sh @@ -1,23 +1,21 @@ apk add jq curl -VAULT_HOST=http://0.0.0.0:8200 - -root_token=$(cat /helpers/keys.json | jq -r '.root_token') +VAULT_HOST=http://127.0.0.1:8200 unseal_vault() { - export VAULT_TOKEN=$root_token + root_token=$(cat /helpers/keys.json | jq -r '.root_token') + vault operator unseal -address=${VAULT_HOST} $(cat /helpers/keys.json | jq -r '.keys[0]') - vault login token=$VAULT_TOKEN + vault login token=$root_token } -if [[ -n "$root_token" ]] +if [[ -f /helpers/keys.json ]] then echo "Vault already initialized" unseal_vault else echo "Vault not initialized" curl -s --request POST --data '{"secret_shares": 1, "secret_threshold": 1}' ${VAULT_HOST}/v1/sys/init > /helpers/keys.json - root_token=$(cat /helpers/keys.json | jq -r '.root_token') unseal_vault