From eb2c93c28cd791a0d322443a110d06b3803697a8 Mon Sep 17 00:00:00 2001 From: Vassiliy Yegorov Date: Wed, 24 Aug 2022 12:36:38 +0700 Subject: [PATCH] add gitlab --- .gitlab-ci.yml | 10 +++++++++ docs/vault-gitlab-ci.md | 48 +++++++++++++++++++++++++++++++++++++++++ 2 files changed, 58 insertions(+) create mode 100644 .gitlab-ci.yml create mode 100644 docs/vault-gitlab-ci.md diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml new file mode 100644 index 0000000..c9a15b9 --- /dev/null +++ b/.gitlab-ci.yml @@ -0,0 +1,10 @@ +read_secrets: + image: vault:latest + script: + - echo $CI_COMMIT_REF_NAME + - echo $CI_COMMIT_REF_PROTECTED + - export VAULT_ADDR=http://vault.bildme.ru + - export VAULT_TOKEN="$(vault write -field=token auth/jwt/login role=gitlabci-role jwt=$CI_JOB_JWT)" + - export PASSWORD="$(vault kv get -field=password secret/gitlab/db1)" + - echo $PASSWORD + when: manual diff --git a/docs/vault-gitlab-ci.md b/docs/vault-gitlab-ci.md new file mode 100644 index 0000000..42c2591 --- /dev/null +++ b/docs/vault-gitlab-ci.md @@ -0,0 +1,48 @@ +# Подключаем внешний вольт к Gitlab-CI + +1. настраиваем метод jwt + +```bash +vault auth enable jwt +vault write auth/jwt/config \ + jwks_url="https://git.realmanual.ru/-/jwks" \ + bound_issuer="git.realmanual.ru" +``` + +2. создаем тестовый секрет + +```bash +vault kv put secret/gitlab/db1 password='pa$$w0rd' +``` + +3. настраиваем политику доступа к конкретному секрету + +```bash +vault policy write gitlabci-policy - <