opentelekomcloud-infra / system-config

System config for the Ecosystem infrastructure
GNU General Public License v3.0
6 stars 9 forks source link

Use KMS for auto-unseal of bootstrap Vault #534

Open gtema opened 2 years ago

kucerakk commented 2 years ago

This does not look compatible with OTC KMS as such. Tried to deploy a test vault instance with using OTC KMS for awskms seal, but it received 404

May 10 09:40:25 vault-test vault[3683]: Error parsing Seal configuration: error fetching AWS KMS wrapping key information: :
May 10 09:40:25 vault-test vault[3683]:         status code: 404, request id: