This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
sw:vault [2024/04/26 10:40] tomas [CLI] |
sw:vault [2024/09/10 19:54] (current) tomas [CLI] |
||
---|---|---|---|
Line 4: | Line 4: | ||
==== URL ==== | ==== URL ==== | ||
https:// | https:// | ||
+ | / | ||
Line 9: | Line 10: | ||
**[[https:// | **[[https:// | ||
VAULT_TOKEN ... token pro autorizaci\\ | VAULT_TOKEN ... token pro autorizaci\\ | ||
- | VAULT_SKIP_VERIFY ... ignoruje nevalidní certifikát\\ | + | VAULT_SKIP_VERIFY=true ... ignoruje nevalidní certifikát\\ |
VAULT_ADDR=https:// | VAULT_ADDR=https:// | ||
+ | |||
+ | == systém == | ||
+ | vault secret list ... seznam včech secret enginu\\ | ||
+ | vault list auth/ | ||
+ | vault list identity/ | ||
+ | vault list identity/ | ||
+ | vault list identity/ | ||
+ | vault auth list ... seznam authentikačních mechanizmů\\ | ||
+ | vault auth enable -path=" | ||
+ | vault login -method=userpass user=tomas ... přihlášení pomocí userpass\\ | ||
+ | vault policy list ... seznam policy\\ | ||
+ | vault policy read aaa ... ukáže definici policy aaa\\ | ||
+ | vault token capabilities secret/ | ||
+ | vault write -format=json identity/ | ||
+ | vault write identity/ | ||
+ | vault audit enable file file_path=/ | ||
+ | vault event subscribe kv-v2/ | ||
+ | wss:// | ||
+ | wscat -H " | ||
+ | |||
== Práce se secretama a hodnotama == | == Práce se secretama a hodnotama == | ||
Line 22: | Line 43: | ||
vault read auth/ | vault read auth/ | ||
vault read sys/ | vault read sys/ | ||
+ | vault print token ... vypíše hodnotu tokenu\\ | ||
== Práce s Vault službou == | == Práce s Vault službou == | ||
Line 33: | Line 55: | ||
== Vault v Dockeru, backup/ | == Vault v Dockeru, backup/ | ||
docker volume create vault-volume\\ | docker volume create vault-volume\\ | ||
- | docker run --rm -it --name vault_local --cap-add=IPC_LOCK -e VAULT_ADDR=' | + | %%docker run --rm -it --name vault_local --cap-add=IPC_LOCK -e VAULT_ADDR=' |
docker cp vault-snap/ | docker cp vault-snap/ | ||
docker exec -it vault_local /bin/sh\\ | docker exec -it vault_local /bin/sh\\ |