Skip to content
  • Matthew Mosesohn's avatar
    refactor vault role (#2733) · 07cc9819
    Matthew Mosesohn authored
    * Move front-proxy-client certs back to kube mount
    
    We want the same CA for all k8s certs
    
    * Refactor vault to use a third party module
    
    The module adds idempotency and reduces some of the repetitive
    logic in the vault role
    
    Requires ansible-modules-hashivault on ansible node and hvac
    on the vault hosts themselves
    
    Add upgrade test scenario
    Remove bootstrap-os tags from tasks
    
    * fix upgrade issues
    
    * improve unseal logic
    
    * specify ca and fix etcd check
    
    * Fix initialization check
    
    bump machine size
    07cc9819
Loading