Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
Last revision Both sides next revision
sw:vault [2023/12/13 17:50]
tomas [CLI]
sw:vault [2024/04/26 10:43]
tomas [CLI]
Line 31: Line 31:
 vault operator generate-root ... zadají se 3 unseal klíče a vygeneruje se nový root klíč\\ vault operator generate-root ... zadají se 3 unseal klíče a vygeneruje se nový root klíč\\
  
 +== Vault v Dockeru, backup/restore == 
 +docker volume create vault-volume\\ 
 +%%docker run --rm -it --name vault_local --cap-add=IPC_LOCK -e VAULT_ADDR='http://0.0.0.0:8200' -e 'VAULT_LOCAL_CONFIG={"storage": {"raft": {"path": "/vault/"}}, "listener": [{"tcp": { "address": "0.0.0.0:8200", "tls_disable": true}}], "default_lease_ttl": "168h", "max_lease_ttl": "720h", "ui": true, "cluster_addr": "http://127.0.0.1:8201", "api_addr": "http://0.0.0.0:8200"}' -p 8200:8200 -v vault-volume:/vault hashicorp/vault:1.14.10 server%%\\ 
 +docker cp vault-snap/vault-raft-2023-11-24-14-45-00.snapshot vault_local:/tmp\\ 
 +docker exec -it vault_local /bin/sh\\ 
 +vault status\\ 
 +vault operator init\\ 
 +vault operator unseal -tls-skip-verify\\ 
 +vault login\\ 
 +vault operator raft snapshot restore -force /tmp/vault-raft-2023-10-09-23-45-00.snapshot\\ 
 +vault operator unseal -tls-skip-verify\\