vault-ops/infra/config/apps.example.yaml
2026-04-14 11:12:12 +07:00

59 lines
1.8 KiB
YAML

environments:
test:
vault_addr: "https://vault-test.example.invalid:22300"
vault_sni: "vault.test.example.invalid"
vault_user: "vault"
vault_group: "vault"
tls_dir: "/home/vault/tls-test"
offline_root_dir: "/root/vault/offline-root/test"
server_chain_path: "/home/vault/tls-test/ca_chain.pem"
kv_mount: "kv-test"
pki_mount: "pki-test"
proxy:
user: "proxytest"
listen_port: 7701
chain_path: "/home/proxytest/nginx/ca/current-ca-chain.pem"
reload: "podman:proxytest"
app:
user: "apptest"
sidecar_host_port: 22288
sidecar_container: "app-sidecar-test"
prod:
vault_addr: "https://vault-prod.example.invalid:22400"
vault_sni: "vault.prod.example.invalid"
vault_user: "vaultprod"
vault_group: "vaultprod"
tls_dir: "/home/vaultprod/tls-prod"
offline_root_dir: "/root/vault/offline-root/prod"
server_chain_path: "/home/vaultprod/tls-prod/ca_chain.pem"
kv_mount: "kv-prod"
pki_mount: "pki-prod"
proxy:
user: "proxyprod"
listen_port: 8701
chain_path: "/home/proxyprod/nginx/ca/current-ca-chain.pem"
reload: "podman:proxyprod"
app:
user: "appprod"
sidecar_host_port: 32288
sidecar_container: "app-sidecar-prod"
apps:
- name: "exampleapp"
user: "exampleapp"
internal_cn: "exampleapp.int.example.invalid"
external_host_test: "exampleapp.test.example.invalid"
external_host_prod: "exampleapp.prod.example.invalid"
issue_ttl: "24h"
- name: "examplekv"
user: "examplekv"
kv_subpaths:
- examplekv/postgres
- examplekv/app
cert_map_name: "agent-examplekv"
internal_cn: "examplekv.int.example.invalid"
external_host_test: "examplekv.test.example.invalid"
external_host_prod: "examplekv.prod.example.invalid"
issue_ttl: "24h"