Sign inSign up

sitch/self_signed_seeder

By sitch

•Updated almost 10 years ago

Creates self-signed certs for Logstash, inserts into Vault.

Image
0

10K+

sitch/self_signed_seeder repository overview

⁠Sitch Self-Signed Seeder

⁠A task for generating self-signed crypto material for Logstash, and injecting into Vault

⁠Designed for use with SITCH Sensor Mk3

You'll need the following environment variable set:

VariablePurpose
VAULT_URLURL for vault server
VAULT_TOKENRoot token for vault
LS_CLIENTNAMECN for Logstash client
LS_SERVERNAMECN for Logstash server

Here's the skinny: Run this task with the right creds and you'll be returned the following on stdout:

  • logstash server vault token
  • logstash client vault token

These will give you access to the credentials auto-generated by this tool and inserted into your Vault. The paths for accessing these credentials are:

PathPurpose
/server/certLogstash server certifcate
/server/keyLogstash server key
/client/caCA certificate for client
/client/certLogstash client certificate
/client/keyLogstash client key

The first portion of the path represents the token required to access the credential.

This goes into your sitch sensor and logstash server configuration. Using this will allow a rapid re-key of your log delivery infrastructure. Create a new Vault and kick this off. When it completes, place the tokens in your delivery system (resin.io application environment variable for the sensor, and whatever your container orchestration system is for the Logstash server). Then restart your Logstash server container and Resin application with the new credentials. Voila.

Tag summary

Content type

Image

Digest

Size

17.8 MB

Last updated

almost 10 years ago

docker pull sitch/self_signed_seeder