4 ms·
Thanks for vault. Thievish why we use it. Only for bootstrapping the TLS key of the vault servers we needed another tool. Sure there is sops. We opted for go
by weitzj 6y ago
Thanks for vault. Thievish why we use it.
Only for bootstrapping the TLS key of the vault servers we needed another tool.
Sure there is sops.
We opted for google/tink
This gives us asymmetric encryption with KMS for bootstrapping the vault AMIs on AWS.
We create Vault AMIs with Packer and put encrypted TLS keys inside the AMIs.
This way we have immutable machine images, which can crash/restart using an Autoscaling group and we can attach all decryption processes to the instance role of the EC2 machines