27 Commits (82a28d6bb305b57e8ca90523a44609b870b7b663)

Author SHA1 Message Date
Di Xu 1081f620d2 add support for non-amd64 arch gcr.io images 6 years ago
Matthew Mosesohn 07cc981971
refactor vault role (#2733) 6 years ago
Chad Swenson d87b6fd9f3 Use dedicated front-proxy-ca for front-proxy-client 6 years ago
Matthew Mosesohn 03bcfa7ff5
Stop templating kube-system namespace and creating it (#2545) 6 years ago
mirwan ee8f678010 Addition of the .creds extension to the credentials files generated by password lookup in order for Ansible not to consider them as inventory files with inventory_ignore_extensions set accordingly (#2446) 6 years ago
Brad Beam c874f16c02 Fixing credential lookup for fe proxy and vault (#2361) 6 years ago
Wong Hoi Sing Edison 1a1d154e14 Support multiple inventory files under individual inventory directory 6 years ago
woopstar f9df692056 Issue front proxy certs for vault 6 years ago
Matthew Mosesohn 16629d0b8e Vault should use cert auth for etcd 6 years ago
Matthew Mosesohn bfb25fa47b
Change vault cert ttl to 8y (#2013) 6 years ago
Brad Beam d3850a4da5 Fixing alt_names for vault cert generation 6 years ago
Matthew Mosesohn 4d3326b542
Raise default vault lease TTL to 10y (#2008) 6 years ago
abelgana e7173e1d62
Change altnames to alt_names 6 years ago
Hassan Zamani 3acc42c5b3 Use etcd_access_addresses for vault_etcd_url 7 years ago
Brad Beam 4b587aaf99 Adding ability to specify altnames for vault cert (#1640) 7 years ago
Maxim Krasilnikov e16b57aa05 Store vault users passwords to credentials dir. Create vault and etcd roles after start vault cluster (#1632) 7 years ago
mkrasilnikov 3acb86805b Rename vault_address to vault_bind_address 7 years ago
mkrasilnikov bf0af1cd3d Vault role updates: 7 years ago
Maxim Krasilnikov 6eb22c5db2 Change single Vault pki mount to multi pki mounts paths for etcd and kube CA`s (#1552) 7 years ago
Brad Beam 8b151d12b9 Adding yamllinter to ci steps (#1556) 7 years ago
Brad Beam e5cfdc648c Adding ability to override max ttl (#1559) 7 years ago
Maxim Krasilnikov 2ba285a544 Fixed deploy cluster with vault cert manager (#1548) 7 years ago
Josh Conant 245e05ce61 Vault security hardening and role isolation 7 years ago
Josh Conant f4ec2d18e5 Adding the Vault role 7 years ago