2017-05-25 166 views
0

我想在AWS後端使用Hashicorp的Vault。我已經自動啓動Vault的過程。如果保險庫永遠封閉,我是否必須再次安裝AWS後端?金庫密封時是否需要重新安裝後端?

基本上,當金庫密封時,坐騎是否可以卸載?

我只是想弄清楚是否需要將mount命令添加到我的unseal自動化中。

回答

1

我自己找到了答案。我會在這裏發佈給其他人看。

後端不會自動卸載。事實上,the documentation指出umounting後端銷燬所有數據:

當祕密後端被卸載,它的所有祕密被撤銷(如果支持的話),以及所有存儲在該後端數據物理存儲層被刪除。

如果密封保險櫃也會破壞您的所有數據,這將是非常糟糕的。嘿嘿。

我能測試此我自己:

[[email protected] ~]$ vault mount aws 
Successfully mounted 'aws' at 'aws'! 

[[email protected] ~]$ vault mounts 
Path  Type  Default TTL Max TTL Force No Cache Replication Behavior Description 
aws/  aws  system  system false   replicated 
secret/  generic system  system false   replicated   generic secret storage 
sys/  system  n/a   n/a  false   replicated   system endpoints used for control, policy and debugging 

[[email protected] ~]$ vault seal 
Vault is now sealed. 

[[email protected] ~]$ vault unseal 
Key (will be hidden): 

[[email protected] ~]$ vault mounts 
Path  Type  Default TTL Max TTL Force No Cache Replication Behavior Description 
aws/  aws  system  system false   replicated 
secret/  generic system  system false   replicated   generic secret storage 
sys/  system  n/a   n/a  false   replicated   system endpoints used for control, policy and debugging 
相關問題