Sign inSign up

rittme/vault-orca

By rittme

•Updated about 6 years ago

hashicorp vault unsealer

Image
0

397

rittme/vault-orca repository overview

⁠Vault Orca

vault orca

Vault Orca is a simple docker image to watch and unseal a Hashicorp Vault server when available. Each orca container own one key share.

This image is not safe, since you are exposing your unseal keys on docker-compose. Don't use it on production.

⁠Usage

To use Vault Orca you need to set 3 environment variables:

  • VAULT_URL: the vault server URL
  • UNSEAL_KEY: the master key share that belongs to this container
  • MINUTES: the delay between unseal checks

If you need to use a self signed certificate for TLS, you can mount it at /usr/local/share/ca-certificates.

⁠Example docker-compose

version: '3'

services:
  orca:
    container_name: orca
    image: alpine:3.11
    command: crond -f -l 8
    environment:
      VAULT_URL: https://vault.example:8200
      UNSEAL_KEY: KEY
      MINUTES: 5
    volumes:
      - /certs:/usr/local/share/ca-certificates:ro

Tag summary

Content type

Image

Digest

Size

5.7 MB

Last updated

about 6 years ago

docker pull rittme/vault-orca