{"id":251714,"date":"2023-10-25T02:38:19","date_gmt":"2023-10-24T18:38:19","guid":{"rendered":"https:\/\/www.idc.net\/help\/251714\/"},"modified":"2023-10-25T02:38:19","modified_gmt":"2023-10-24T18:38:19","slug":"%e4%b8%80%e7%af%87%e5%ad%a6%e4%bc%9a-hashicorp-vault-%e7%b3%bb%e7%bb%9f","status":"publish","type":"post","link":"https:\/\/idc.net\/help\/251714\/","title":{"rendered":"\u4e00\u7bc7\u5b66\u4f1a HashiCorp Vault \u7cfb\u7edf"},"content":{"rendered":"<h4>\u662f\u4ec0\u4e48<\/h4>\n<p style=\"text-align: justify\">HashiCorp Vault \u662f\u4e00\u4e2a\u7528\u4e8e\u7ba1\u7406\u5bc6\u7801\u3001\u5bc6\u94a5\u548c\u8bc1\u4e66\u7b49\u79d8\u5bc6\u7684\u7cfb\u7edf\uff0c\u540c\u65f6\u8fd8\u53ef\u63d0\u4f9b\u6709\u8eab\u4efd\u8ba4\u8bc1\u548c\u6388\u6743\u4fdd\u62a4\u7684\u52a0\u5bc6\u670d\u52a1\u3002\u5229\u7528 Vault \u63d0\u4f9b\u7684UI\u3001CLI\u6216HTTP API\uff0c\u53ef\u4ee5\u5728\u4e25\u683c\u7684\u63a7\u5236\u548c\u5ba1\u8ba1\u4e0b\u5b89\u5168\u5730\u5b58\u50a8\u548c\u7ba1\u7406\u654f\u611f\u6570\u636e\u3002<\/p>\n<h4>\u4e3a\u4ec0\u4e48<\/h4>\n<p style=\"text-align: justify\">\u5728\u73b0\u4ee3\u7cfb\u7edf\u4e2d\uff0c\u9700\u8981\u8bf8\u5982\u6570\u636e\u5e93\u8bbf\u95ee\u51ed\u8bc1\u3001\u5916\u90e8API\u8bbf\u95ee\u5bc6\u94a5\u3001\u670d\u52a1\u95f4\u8c03\u7528\u51ed\u8bc1\u7b49\u591a\u79cd\u5927\u91cf\u79d8\u5bc6\u4fe1\u606f\uff0c\u8fd9\u4e9b\u4fe1\u606f\u5206\u6563\u5b58\u50a8\u5728\u7eaf\u6587\u672c\u3001\u914d\u7f6e\u6587\u4ef6\u3001\u6e90\u4ee3\u7801\u6216\u5176\u4ed6\u4f4d\u7f6e\u3002\u5982\u679c\u6ca1\u6709\u4e13\u95e8\u7684\u89e3\u51b3\u65b9\u6848\uff0c\u4ec5\u9760\u6563\u843d\u5728\u5404\u5e73\u53f0\u81ea\u8eab\u7684\u673a\u5236\uff0c\u5f88\u96be\u5f04\u6e05\u695a\u8c01\u5728\u8bbf\u95ee\u54ea\u4e9b\u5bc6\u94a5\uff0c\u5f88\u96be\u505a\u597d\u5b89\u5168\u5b58\u50a8\u3001\u5bc6\u94a5\u8f6e\u6362\u548c\u5b89\u5168\u5ba1\u8ba1\u7b49\u5de5\u4f5c\u3002<\/p>\n<p style=\"text-align: justify\">Vault \u901a\u8fc7\u5c06\u6240\u6709\u8fd9\u4e9b\u51ed\u636e\u96c6\u4e2d\u8d77\u6765\uff0c\u5728\u4e00\u4e2a\u5730\u65b9\u5b9a\u4e49\uff0c\u51cf\u5c11\u4e86\u4e0d\u5fc5\u8981\u7684\u66b4\u9732\uff0c\u5e76\u63d0\u4f9b\u4e86\u8bbf\u95ee\u7684\u5b89\u5168\u6027\u548c\u5ba1\u8ba1\u7684\u65b9\u4fbf\u6027\u3002<\/p>\n<h4>\u5de5\u4f5c\u539f\u7406<\/h4>\n<p style=\"text-align: justify\">Vault \u4e3b\u8981\u901a\u8fc7\u4e0e\u5b89\u5168\u7b56\u7565\u5173\u8054\u7684\u4ee4\u724c\u6765\u63a7\u5236\u5ba2\u6237\u7aef\u5bf9\u79d8\u5bc6\u7684\u8bbf\u95ee\u3002\u5b89\u5168\u7b56\u7565\u7531\u4e00\u7ec4\u63cf\u8ff0\u8def\u5f84\u53ca\u5176\u64cd\u4f5c\u53ef\u8bbf\u95ee\u6027\u7684\u5b89\u5168\u89c4\u5219\u7ec4\u6210\u3002\u4ee4\u724c\u53ef\u4ee5\u624b\u52a8\u521b\u5efa\u5e76\u6388\u4e88\u5ba2\u6237\u7aef\uff0c\u4e5f\u53ef\u4ee5\u7531\u5ba2\u6237\u7aef\u901a\u8fc7\u767b\u5f55\u81ea\u884c\u83b7\u53d6\u3002\u3002<\/p>\n<p style=\"text-align:center\">\n<p style=\"text-align: justify\">Vault \u7684\u6838\u5fc3\u5de5\u4f5c\u6d41\u4e3a\uff1a<\/p>\n<ul>\n<li>\u5ba2\u6237\u7aef\u63d0\u4f9b\u8eab\u4efd\u8bc6\u522b\u4fe1\u606f<\/li>\n<li>Vault \u901a\u8fc7 LDAP\u3001GitHub\u3001AppRole \u7b49\u53ef\u4fe1\u7b2c\u4e09\u65b9\u9a8c\u8bc1\u5ba2\u6237\u7aef<\/li>\n<li>Vault \u5c06\u5b9a\u4e49\u597d\u7684\u5b89\u5168\u7b56\u7565\u5173\u8054\u5230\u4ee4\u724c\uff0c\u5e76\u6388\u4e88\u5ba2\u6237\u7aef<\/li>\n<li>\u5ba2\u6237\u7aef\u901a\u8fc7\u4ee4\u724c\u8bbf\u95ee\u79d8\u5bc6<\/li>\n<\/ul>\n<p style=\"text-align:center\">\n<h4>\u529f\u80fd\u7279\u6027<\/h4>\n<ul>\n<li><strong>\u5b89\u5168\u5b58\u50a8<\/strong><\/li>\n<\/ul>\n<p style=\"text-align: justify\">Vault \u5728\u5bf9\u79d8\u5bc6\u6570\u636e\u6301\u4e45\u5b58\u50a8\u4e4b\u524d\u4f1a\u5bf9\u5176\u8fdb\u884c\u52a0\u5bc6\uff0c\u56e0\u6b64\u5176\u539f\u59cb\u5b58\u50a8\u4e5f\u662f\u5b89\u5168\u7684\u3002<\/p>\n<ul>\n<li><strong>\u52a8\u6001\u79d8\u5bc6<\/strong><\/li>\n<\/ul>\n<p style=\"text-align: justify\">Vault \u53ef\u4e3a AWS\u3001SQL \u6570\u636e\u5e93\u7b49\u7cfb\u7edf\u63d0\u4f9b\u4e34\u65f6\u8bbf\u95ee\u51ed\u636e\uff0c\u5e76\u5728\u5230\u671f\u540e\u4f5c\u5e9f\u3002<\/p>\n<ul>\n<li><strong>\u52a0\u5bc6\u670d\u52a1<\/strong><\/li>\n<\/ul>\n<p style=\"text-align: justify\">Vault \u4e5f\u53ef\u4ee5\u6839\u636e\u5b89\u5168\u56e2\u961f\u5b9a\u4e49\u7684\u52a0\u5bc6\u53c2\u6570\u63d0\u4f9b\u516c\u5171\u7684\u6570\u636e\u7684\u52a0\u5bc6\u3001\u89e3\u5bc6\u670d\u52a1\uff0c\u800c\u4e0d\u5fc5\u5b58\u50a8\u52a0\u89e3\u5bc6\u6570\u636e\u3002<\/p>\n<ul>\n<li><strong>\u79df\u8d41\u4e0e\u7eed\u79df<\/strong><\/li>\n<\/ul>\n<p style=\"text-align: justify\">Vault \u4f7f\u7528\u79df\u671f\u7ba1\u7406\u5b58\u50a8\u5176\u4e2d\u7684\u5404\u79cd\u79d8\u5bc6\uff0c\u5230\u671f\u524d\u6ca1\u6709\u88ab\u7eed\u79df\u7684\u79d8\u5bc6\u5c06\u5e9f\u5f03\u3002<\/p>\n<ul>\n<li><strong>\u5e9f\u5f03<\/strong><\/li>\n<\/ul>\n<p style=\"text-align: justify\">Vault \u5141\u8bb8\u4e3b\u52a8\u5e9f\u5f03\u5355\u4e2a\u3001\u76f8\u5173\u3001\u7279\u5b9a\u7c7b\u578b\u7684\u79d8\u5bc6\uff0c\u5b9e\u73b0\u5bc6\u94a5\u8f6e\u6362\u6216\u9501\u5b9a\u7cfb\u7edf\uff0c\u4ee5\u9632\u8303\u5165\u4fb5\u3002<\/p>\n<h4>\u7248\u672c<\/h4>\n<p style=\"text-align: justify\">Vault \u5171\u6709\u5f00\u6e90\u7248\u3001\u4e91\u6258\u7ba1\u7248\u548c\u4f01\u4e1a\u72483\u79cd\u7248\u672c\u3002<\/p>\n<p style=\"text-align: justify\">\u5f00\u6e90\u7248\u9700\u8981\u81ea\u6258\u7ba1\uff0c\u63d0\u4f9b\u52a8\u6001\u79d8\u5bc6\u7ba1\u7406\u3001\u52a0\u5bc6\u548c\u6570\u636e\u4fdd\u62a4\u7b49\u57fa\u672c\u529f\u80fd\u7279\u6027\uff0c\u9700\u8981\u901a\u8fc7\u793e\u533a\u83b7\u5f97\u652f\u6301\u3002<\/p>\n<p style=\"text-align: justify\">\u4e91\u6258\u7ba1\u7248\u672c\uff0c\u540d\u4e3a HCP Vault\uff08HashiCorp Cloud Platform Vault\uff09\uff0c\u4e0e\u81ea\u6258\u7ba1 Vault \u5177\u6709\u76f8\u540c\u7684\u4e8c\u8fdb\u5236\u6587\u4ef6\uff0c\u5728\u4fdd\u8bc1\u4e00\u81f4\u7528\u6237\u4f53\u9a8c\u7684\u540c\u65f6\uff0c\u5141\u8bb8\u7ec4\u7ec7\u5feb\u901f\u4f7f\u7528 Vault\u3002<\/p>\n<p style=\"text-align: justify\">\u4f01\u4e1a\u7248\u9700\u8981\u81ea\u6258\u7ba1\uff0c\u6bd4\u5f00\u6e90\u7248\u591a\u4e86\u6269\u5c55\u3001\u5bb9\u707e\u7b49\u4f01\u4e1a\u7279\u6027\uff0c\u5e76\u7531HashiCorp\u63d0\u4f9b\u670d\u52a1\u652f\u6301\u3002<\/p>\n<h3>\u5feb\u901f\u4f53\u9a8c<\/h3>\n<h4>\u5b89\u88c5<\/h4>\n<pre># \u5b89\u88c5 yum<span style=\"color: #d73a49\">-<\/span>config<span style=\"color: #d73a49\">-<\/span>manager \u6765\u7ba1\u7406\u5b58\u50a8\u5e93\u3002<br>sudo yum install <span style=\"color: #d73a49\">-<\/span>y yum<span style=\"color: #d73a49\">-<\/span>utils<br># \u4f7f\u7528 yum<span style=\"color: #d73a49\">-<\/span>config<span style=\"color: #d73a49\">-<\/span>manager \u6dfb\u52a0\u5b98\u65b9\u7684 HashiCorp Linux \u5b58\u50a8\u5e93\u3002<br>sudo yum<span style=\"color: #d73a49\">-<\/span>config<span style=\"color: #d73a49\">-<\/span>manager <span style=\"color: #6a737d\">--add-repo https:\/\/rpm.releases.hashicorp.com\/RHEL\/hashicorp.repo<\/span><br><br># \u5b89\u88c5<br>sudo yum <span style=\"color: #d73a49\">-<\/span>y install vault<br># \u6216\u8005\u5b89\u88c5\u4f01\u4e1a\u7248<br>sudo yum <span style=\"color: #d73a49\">-<\/span>y install vault<span style=\"color: #d73a49\">-<\/span>enterprise <br><br># \u9a8c\u8bc1<br>vault<\/pre>\n<h4>\u542f\u52a8<\/h4>\n<pre># \u67e5\u770b\u542f\u52a8\u5e2e\u52a9<br>vault server <span style=\"color: #d73a49\">-<\/span>help<br><br># \u4ee5\u5f00\u53d1\u6a21\u5f0f\u542f\u52a8\uff0c\u6570\u636e\u4ecd\u7136\u52a0\u5bc6\uff0c\u4f46\u4fdd\u5b58\u5728\u5185\u5b58\u4e2d\uff0c\u4f7f\u7528http\u4fa6\u542c\uff0c\u4ec5\u7528\u4e8e\u5feb\u901f\u4f53\u9a8c\uff0c\u4e0d\u80fd\u7528\u4e8e\u751f\u4ea7<br>vault server <span style=\"color: #d73a49\">-<\/span>dev<br><br># \u8bb0\u5f55\u65e5\u5fd7\u4e2d\u8f93\u51fa\u7684VAULT_ADDR\u3001Unseal Key\u3001Root Token<br><br># \u5728\u4e00\u4e2a\u65b0\u7ec8\u7aef\u4e2d\u8fdb\u884c\u5982\u4e0b\u64cd\u4f5c<br># \u7559\u5b58Unseal Key\u5230\u67d0\u4e2a\u5730\u65b9<br>echo <span style=\"color: #690\">\"\u628a\u8fd9\u6bb5\u6587\u5b57\u7528Unseal Key\u66ff\u6362\"<\/span> <span style=\"color: #d73a49\">&gt;<\/span> unseal<span style=\"color: #005cc5\">.key<\/span><br># \u6839\u636eserver\u542f\u52a8\u65e5\u5fd7\u4e2d\u7684\u4fe1\u606f\u8bbe\u7f6e\u73af\u5883\u53d8\u91cfVAULT_ADDR\uff0c\u8868\u793aserver\u7684\u8bbf\u95ee\u5730\u5740<br>export VAULT_ADDR<span style=\"color: #d73a49\">=<\/span><span style=\"color: #690\">'http:\/\/127.0.0.1:8200'<\/span><br># \u6839\u636eserver\u542f\u52a8\u65e5\u5fd7\u4e2d\u7684\u4fe1\u606f\u8bbe\u7f6e\u73af\u5883\u53d8\u91cfVAULT_TOKEN\uff0c\u8868\u793aroot\u8bbf\u95ee\u4ee4\u724c<br>export VAULT_TOKEN<span style=\"color: #d73a49\">=<\/span><span style=\"color: #690\">\"\u7528Root Token\u66ff\u6362\u8fd9\u6bb5\u6587\u5b57\"<\/span><br><br># \u67e5\u770b\u670d\u52a1\u72b6\u6001<br>vault status<\/pre>\n<h4>\u5904\u7406\u952e\u503c\u5bf9secret<\/h4>\n<pre># \u67e5\u770b\u5904\u7406\u952e\u503c\u5bf9\u7684\u547d\u4ee4\u5e2e\u52a9<br>vault kv <span style=\"color: #d73a49\">-<\/span>help <br># \u67e5\u770bput\u952e\u503c\u5bf9\u547d\u4ee4\u5e2e\u52a9<br>vault kv put <span style=\"color: #d73a49\">-<\/span>help<br><br># \u521b\u5efa\u4e00\u4e2a\u540d\u4e3ahell\u3001\u5305\u542bfoo\u3001excited\u4e24\u4e2aKey\u7684\u952e\u503c\u5bf9secret\u3002<br># \u6bcf\u9488\u5bf9\u540c\u540dsecret put\u4e00\u6b21\uff0c\u5176\u5143\u6570\u636e\u4e2d\u7684version\u5c31\u4f1a\u9012\u589e<br>vault kv put <span style=\"color: #d73a49\">-<\/span>mount<span style=\"color: #d73a49\">=<\/span>secret hello foo<span style=\"color: #d73a49\">=<\/span>world excited<span style=\"color: #d73a49\">=<\/span>yes<br><br># \u8bfb\u53d6\u540d\u4e3ahello\u7684\u952e\u503c\u5bf9secret\uff0c\u54cd\u5e94\u4e2d\u4f1a\u663e\u793a\u5176\u5143\u6570\u636e\u548c\u952e\u503c\u6570\u636e<br>vault kv get <span style=\"color: #d73a49\">-<\/span>mount<span style=\"color: #d73a49\">=<\/span>secret hello<br># \u8bfb\u53d6kv\u4e2dexcited\u952e\u7684\u503c<br>vault kv get <span style=\"color: #d73a49\">-<\/span>mount<span style=\"color: #d73a49\">=<\/span>secret <span style=\"color: #d73a49\">-<\/span>field<span style=\"color: #d73a49\">=<\/span>excited hello<br># \u4ee5json\u683c\u5f0f\u8f93\u51fa\uff0c\u5e76\u4f7f\u7528jq\u547d\u4ee4\u63d0\u53d6excited\u8fd9\u4e2akey\u7684\u6570\u636e<br>vault kv get <span style=\"color: #d73a49\">-<\/span>mount<span style=\"color: #d73a49\">=<\/span>secret <span style=\"color: #d73a49\">-<\/span>format<span style=\"color: #d73a49\">=<\/span>json hello <span style=\"color: #d73a49\">|<\/span> jq <span style=\"color: #d73a49\">-<\/span>r <span style=\"color: #005cc5\">.data<\/span><span style=\"color: #005cc5\">.data<\/span><span style=\"color: #005cc5\">.excited<\/span><br><br># \u5220\u9664\u540d\u4e3ahello\u7684\u952e\u503c\u5bf9secret<br>vault kv <span style=\"color: #d73a49\">delete<\/span> <span style=\"color: #d73a49\">-<\/span>mount<span style=\"color: #d73a49\">=<\/span>secret hello<br><br># \u6062\u590d\u65e0\u610f\u5220\u9664\u7684\u540d\u4e3ahello\u7684secret\u5230\u7b2c2\u4e2a\u7248\u672c<br>vault kv undelete <span style=\"color: #d73a49\">-<\/span>mount<span style=\"color: #d73a49\">=<\/span>secret <span style=\"color: #d73a49\">-<\/span>versions<span style=\"color: #d73a49\">=<\/span><span style=\"color: #005cc5\">2<\/span> hello<\/pre>\n<h3>\u5f15\u64ce<\/h3>\n<p style=\"text-align: justify\">\u79d8\u5bc6\u5f15\u64ce\u662f Vault \u7528\u4e8e\u50a8\u5b58\u3001\u751f\u6210\u548c\u52a0\u89e3\u5bc6\u7684\u63d2\u4ef6\u5316\u7684\u7ec4\u4ef6\uff0c\u952e\u503c\u53ea\u662f\u5176\u4e2d\u4e00\u79cd\uff0c\u5176\u5b83\u5b58\u50a8\u5f15\u64ce\u8fd8\u6709\u6570\u636e\u5e93\u3001Transit\uff08\u52a0\u89e3\u5bc6\u670d\u52a1\u5f15\u64ce\uff09\u3001SSH\u3001Time-baseed OTP\u3001AWS\u3001Consul\u7b49\uff0c\u4e5f\u53ef\u4ee5\u81ea\u5b9a\u4e49\u3002<\/p>\n<pre># \u79d8\u5bc6\u5f15\u64ce\u9700\u8981\u542f\u7528\u540e\u624d\u80fd\u4f7f\u7528\u3002<br># \u540c\u4e00\u79cd\u5b58\u50a8\u5f15\u64ce\u53ef\u4ee5\u5728\u4e0d\u540c\u7684\u8def\u5f84\uff08path\uff09\u4e0a\u542f\u7528\u3002<br># \u5f00\u53d1\u6a21\u5f0f\u9884\u8bbe\u542f\u7528\u4e86\u952e\u503c\u5f15\u64ce\u3002<br>vault secrets enable -path=kv kv<br><br># \u542f\u7528\u79d8\u5bc6\u5f15\u64ce\u7684\u8def\u5f84\u9ed8\u8ba4\u4e3a\u79d8\u5bc6\u5f15\u64ce\u7684\u540d\u79f0<br>vault secrets enable kv<br><br># \u4ee5\u4e0b\u547d\u4ee4\u7528\u4e8e\u5217\u51fa\u6240\u6709\u79d8\u5bc6\u5f15\u64ce<br>vault secrets list<br><br># \u4ee5\u4e0b\u547d\u4ee4\u4f7f\u7528 path\/\u79d8\u5bc6\u540d\u79f0 \u7684\u5f62\u5f0f\u8bbe\u7f6e\u540d\u4e3ahello\u7684\u952e\u503c\u6570\u636e<br>vault kv put kv\/hello target=world<br><br># \u4ee5\u4e0b\u547d\u4ee4\u53ef\u7981\u7528\u8def\u5f84\u4e3akv\u4e0b\u7684\u79d8\u5bc6\u5f15\u64ce\uff0c\u5e76\u5220\u9664\u5173\u8054\u7684\u79d8\u5bc6\u548c\u914d\u7f6e<br>vault secrets disable kv\/<\/pre>\n<h3>\u751f\u4ea7\u6a21\u5f0f\u5b89\u88c5<\/h3>\n<h4>\u5efa\u7acb\u914d\u7f6e\u6587\u4ef6<\/h4>\n<p style=\"text-align: justify\">Vault\u4f7f\u7528HCL\u6587\u4ef6\u8fdb\u884c\u914d\u7f6e\uff0c\u9996\u5148\u521b\u5efa\u4e00\u4e2aHCL\u914d\u7f6e\u6587\u4ef6\uff0c\u53ef\u4ee5\u547d\u540d\u4e3aconfig.hcl\u3002<\/p>\n<pre>storage <span style=\"color: #690\">\"raft\"<\/span> <span style=\"color: #997\">{<\/span><br>  path    <span style=\"color: #d73a49\">=<\/span> <span style=\"color: #690\">\".\/vault\/data\"<\/span><br>  node_id <span style=\"color: #d73a49\">=<\/span> <span style=\"color: #690\">\"node1\"<\/span><br><span style=\"color: #997\">}<\/span><br><br>listener <span style=\"color: #690\">\"tcp\"<\/span> <span style=\"color: #997\">{<\/span><br>  address         <span style=\"color: #d73a49\">=<\/span> <span style=\"color: #690\">\"[::]:8200\"<\/span><br>  cluster_address <span style=\"color: #d73a49\">=<\/span> <span style=\"color: #690\">\"[::]:8201\"<\/span><br>  tls_cert_file <span style=\"color: #d73a49\">=<\/span> <span style=\"color: #690\">\"\/etc\/certs\/vault.crt\"<\/span><br>  tls_key_file  <span style=\"color: #d73a49\">=<\/span> <span style=\"color: #690\">\"\/etc\/certs\/vault.key\"<\/span><br><span style=\"color: #997\">}<\/span><br><br><br>api_addr <span style=\"color: #d73a49\">=<\/span> <span style=\"color: #690\">\"https:\/\/127.0.0.1:8200\"<\/span><br>cluster_addr <span style=\"color: #d73a49\">=<\/span> <span style=\"color: #690\">\"https:\/\/127.0.0.1:8201\"<\/span><br>ui <span style=\"color: #d73a49\">=<\/span> <span style=\"color: #905\">true<\/span><\/pre>\n<p style=\"text-align: justify\">storage \u6307\u793a\u540e\u7aef\u5b58\u50a8\u65b9\u5f0f\uff0craft \u662f\u4e00\u79cd\u9002\u5408\u751f\u4ea7\u6a21\u5f0f\u7684\u540e\u7aef\u5b58\u50a8\u3002<\/p>\n<p style=\"text-align: justify\">listener \u7528\u4e8e\u914d\u7f6e\u4fa6\u542c API \u8bf7\u6c42\u7684\u5730\u5740\uff0c\u751f\u4ea7\u73af\u5883\u5e94\u542f\u7528 TLS \u3002<\/p>\n<p style=\"text-align: justify\">api_addr \u7528\u4e8e\u5907\u7528\u670d\u52a1\u5668\u5411\u4e3b\u670d\u52a1\u5668\u91cd\u5b9a\u5411\u5ba2\u6237\u7aef\u7684\u5730\u5740\u3002<\/p>\n<p style=\"text-align: justify\">cluster_addr \u4e3a\u540c\u4e00\u96c6\u7fa4\u4e0b\u5404node\u4e92\u76f8\u901a\u4fe1\u7684\u5730\u5740\uff0c\u7528\u4e8e\u5907\u7528\u670d\u52a1\u5668forward\u5ba2\u6237\u7aef\u8bf7\u6c42\u5230\u4e3b\u670d\u52a1\u5668\uff0c\u5fc5\u987b\u4f7f\u7528TLS\u3002<\/p>\n<p style=\"text-align: justify\">ui\u7528\u4e8e\u542f\u7528\u9ed8\u8ba4\u4e0d\u542f\u7528\u7684Web UI\u3002<\/p>\n<p style=\"text-align: justify\">\u4e0d\u652f\u6301\u5185\u5b58\u9501\u5b9a\u65f6\uff0c\u9700\u8981\u6dfb\u52a0\u914d\u7f6e\uff1adisable_mlock = true<\/p>\n<h4>\u5efa\u7acbraft\u5de5\u4f5c\u76ee\u5f55<\/h4>\n<pre>mkdir <span style=\"color: #d73a49\">-<\/span>p .<span style=\"color: #d73a49\">\/<\/span>vault<span style=\"color: #d73a49\">\/<\/span>data<\/pre>\n<h4>\u542f\u52a8\u670d\u52a1\u5668<\/h4>\n<pre>vault server <span style=\"color: #d73a49\">-<\/span>config<span style=\"color: #d73a49\">=<\/span>config<span style=\"color: #005cc5\">.hcl<\/span><\/pre>\n<h4>\u521d\u59cb\u5316<\/h4>\n<p style=\"text-align: justify\">\u542f\u52a8\u4e00\u4e2a\u65b0\u7684\u7ec8\u7aef\uff0c\u5e76\u6267\u884c\u5982\u4e0b\u547d\u4ee4\u4ee5\u521d\u59cb\u5316\u670d\u52a1\u5668\u3002<\/p>\n<pre># \u8bbe\u7f6e\u670d\u52a1API\u5730\u5740<br>export VAULT_ADDR<span style=\"color: #d73a49\">=<\/span><span style=\"color: #690\">'http:\/\/127.0.0.1:8200'<\/span><br># \u521d\u59cb\u5316\u670d\u52a1<br>vault operator init<\/pre>\n<p style=\"text-align: justify\">\u521d\u59cb\u5316\u8fc7\u7a0b\u4f1a\u8f93\u51fa5\u4e2a\u89e3\u5c01\u5bc6\u94a5\u548c1\u4e2aroot\u521d\u59cbToken\uff0c\u9700\u8981\u5b89\u5168\u7684\u5206\u53d1\u5bc6\u94a5\uff0c\u907f\u514d\u4e00\u4e2a\u4eba\u6301\u6709\u6240\u6709\u5bc6\u94a5\uff0c\u4ee5\u4fbf\u5f53Vault\u5bc6\u5c01\u65f6\uff0c\u81f3\u5c11\u9700\u89813\u4e2a\u5bc6\u94a5\u624d\u80fd\u89e3\u5c01\u3002<\/p>\n<h4>\u89e3\u5c01<\/h4>\n<p style=\"text-align: justify\">Vault\u5728\u521d\u59cb\u5316\u540e\uff0c\u4ee5\u53ca\u6bcf\u6b21\u91cd\u542f\u540e\uff0c\u90fd\u9700\u8981\u89e3\u5c01\u624d\u80fd\u8bfb\u53d6\u79d8\u5bc6\u6570\u636e\u3002\u9700\u8981\u5728\u4e0d\u540c\u7684\u8ba1\u7b97\u673a\u4e0a\uff0c\u5206\u522b\u6267\u884c\u5982\u4e0b\u547d\u4ee4\uff0c\u5e76\u5404\u63d0\u4f9b\u4e00\u4e2a\u4e0d\u540c\u7684\u5bc6\u94a5\uff0c\u624d\u80fd\u5b8c\u6210\u89e3\u5c01\u3002<\/p>\n<pre>vault operator unseal<\/pre>\n<h4>\u767b\u5f55<\/h4>\n<p style=\"text-align: justify\">\u4f7f\u7528\u521d\u59cb\u5316\u540e\u83b7\u5f97\u7684Root\u4ee4\u724c\u767b\u5f55Vault\u670d\u52a1\u3002<\/p>\n<pre>vault login<\/pre>\n<h4>\u5176\u5b83\u8fd0\u7ef4\u547d\u4ee4<\/h4>\n<p style=\"text-align: justify\">\u4efb\u4e00\u8fd0\u7ef4\u4eba\u5458\u53ef\u901a\u8fc7\u6267\u884c&nbsp;<span style=\"background-color: #dee0e3\">vault operator seal&nbsp;<\/span>\u547d\u4ee4\u518d\u6b21\u5bc6\u5c01Vault\uff0c\u53ef\u4ee5\u901a\u8fc7\u6267\u884c&nbsp;<span style=\"background-color: #dee0e3\">pgrep -f vault | xargs kill&nbsp;<\/span>\u547d\u4ee4\u7ec8\u6b62 Vault \u8fdb\u7a0b\uff0c\u901a\u8fc7\u6267\u884c&nbsp;<span style=\"background-color: #dee0e3\">rm -r .\/vault\/data<\/span>&nbsp;\u547d\u4ee4\u6e05\u9664 Vault \u6570\u636e\u3002<\/p>\n<p style=\"text-align: justify\">\u4f7f\u7528Transit\u5f15\u64ce\u8fdb\u884c\u52a0\u89e3\u5bc6<\/p>\n<p style=\"text-align: justify\">\u4ee5\u4e0b\u6f14\u793a\u4f7f\u7528Vault Transit\u5f15\u64ce\u8fdb\u884c\u6570\u636e\u52a0\u89e3\u5bc6\uff08\u4e0d\u5b58\u50a8\uff09\u7684\u8fc7\u7a0b\uff0c\u6d89\u53ca\u7ba1\u7406\u5458\u548c\u5ba2\u6237\u7aef\u4e24\u4e2a\u89d2\u8272\u3002<\/p>\n<pre># <span style=\"color: #997\">(<\/span>\u7ba1\u7406\u5458<span style=\"color: #997\">)<\/span> \u4ee5\u5f00\u53d1\u6a21\u5f0f\u53caroot token\u542f\u52a8 Vault<br># \u6ce8\uff1a\u751f\u4ea7\u73af\u5883\u4e2d\uff0c\u5e94\u4f7f\u7528\u5177\u6709\u67d0\u4e9b\u5b89\u5168\u7b56\u7565\u7684\u5176\u5b83Token\u6267\u884c\u672c\u4efb\u52a1<br>vault server <span style=\"color: #d73a49\">-<\/span>dev <span style=\"color: #d73a49\">-<\/span>dev<span style=\"color: #d73a49\">-<\/span>root<span style=\"color: #d73a49\">-<\/span>token<span style=\"color: #d73a49\">-<\/span>id root<br># <span style=\"color: #997\">(<\/span>\u7ba1\u7406\u5458<span style=\"color: #997\">)<\/span> \u4f7f\u7528\u73af\u5883\u53d8\u91cf\u58f0\u660eVault\u670d\u52a1\u7684\u5730\u5740\uff0c\u65b9\u4fbf\u540e\u7eed\u64cd\u4f5c<br>export VAULT_ADDR<span style=\"color: #d73a49\">=<\/span>$VAULT_ADDR<br># <span style=\"color: #997\">(<\/span>\u7ba1\u7406\u5458<span style=\"color: #997\">)<\/span> \u4f7f\u7528\u73af\u5883\u53d8\u91cf\u58f0\u660e\u8981\u4f7f\u7528\u7684\u4ee4\u724c\uff0c\u65b9\u4fbf\u540e\u7eed\u64cd\u4f5c<br>export VAULT_TOKEN<span style=\"color: #d73a49\">=<\/span>root<br><br># <span style=\"color: #997\">(<\/span>\u7ba1\u7406\u5458<span style=\"color: #997\">)<\/span> \u542f\u7528transit\u5f15\u64ce<br>vault secrets enable transit<br># \uff08\u7ba1\u7406\u5458<span style=\"color: #997\">)<\/span> \u542f\u7528\u540d\u4e3aorders\u7684\u52a0\u5bc6\u73af<br>vault write <span style=\"color: #d73a49\">-<\/span>f transit<span style=\"color: #d73a49\">\/<\/span>keys<span style=\"color: #d73a49\">\/<\/span>orders<br><br># \uff08\u7ba1\u7406\u5458<span style=\"color: #997\">)<\/span> \u4e3a\u5ba2\u6237\u7aef\u521b\u5efa\u540d\u4e3aapp<span style=\"color: #d73a49\">-<\/span>orders\u7684\u5b89\u5168\u7b56\u7565<br>vault policy write app<span style=\"color: #d73a49\">-<\/span>orders <span style=\"color: #d73a49\">-&lt;&lt;<\/span>EOF<br>path <span style=\"color: #690\">\"transit\/encrypt\/orders\"<\/span> <span style=\"color: #997\">{<\/span><br>   capabilities <span style=\"color: #d73a49\">=<\/span> <span style=\"color: #997\">[<\/span> <span style=\"color: #690\">\"update\"<\/span> <span style=\"color: #997\">]<\/span><br><span style=\"color: #997\">}<\/span><br>path <span style=\"color: #690\">\"transit\/decrypt\/orders\"<\/span> <span style=\"color: #997\">{<\/span><br>   capabilities <span style=\"color: #d73a49\">=<\/span> <span style=\"color: #997\">[<\/span> <span style=\"color: #690\">\"update\"<\/span> <span style=\"color: #997\">]<\/span><br><span style=\"color: #997\">}<\/span><br>EOF<br># \uff08\u7ba1\u7406\u5458\uff09\u4e3aapp<span style=\"color: #d73a49\">-<\/span>orders\u5b89\u5168\u7b56\u7565\u521b\u5efa\u4e00\u4e2a\u4ee4\u724c<br>vault token <span style=\"color: #d73a49\">create<\/span> <span style=\"color: #d73a49\">-<\/span>policy<span style=\"color: #d73a49\">=<\/span>app<span style=\"color: #d73a49\">-<\/span>orders<br><br># \uff08\u5ba2\u6237\u7aef\uff09\u4f7f\u7528\u73af\u5883\u53d8\u91cf\u5b58\u50a8\u7ba1\u7406\u5458\u5206\u914d\u7684\u4ee4\u724c<br>export APP_ORDER_TOKEN<span style=\"color: #d73a49\">=<\/span><span style=\"color: #690\">\"hvs.CAESIOVYYt5Cq5E0zZX3QVHEv5EYj94pGkGipUX48rI_f2wFGh4KHGh2cy5kdlhPSEhyR2pLa0hlODQwRDVkMzVuMWE\"<\/span><br><br># \uff08\u5ba2\u6237\u7aef\uff09\u5bf9\u660e\u6587base64\u7f16\u7801\u540e\uff0c\u518d\u8c03\u7528Vault\u670d\u52a1\u8fdb\u884c\u52a0\u5bc6<br>VAULT_TOKEN<span style=\"color: #d73a49\">=<\/span>$APP_ORDER_TOKEN vault write transit<span style=\"color: #d73a49\">\/<\/span>encrypt<span style=\"color: #d73a49\">\/<\/span>orders \\<br>    plaintext<span style=\"color: #d73a49\">=<\/span>$<span style=\"color: #997\">(<\/span>base64 <span style=\"color: #d73a49\">&lt;&lt;&lt;<\/span> <span style=\"color: #690\">\"4111 1111 1111 1111\"<\/span><span style=\"color: #997\">)<\/span><br><br># \uff08\u5ba2\u6237\u7aef\uff09\u8c03\u7528Vault\u670d\u52a1\u5bf9\u5bc6\u6587\u8fdb\u884c\u89e3\u5bc6<br>VAULT_TOKEN<span style=\"color: #d73a49\">=<\/span>$APP_ORDER_TOKEN vault write transit<span style=\"color: #d73a49\">\/<\/span>decrypt<span style=\"color: #d73a49\">\/<\/span>orders \\<br>    ciphertext<span style=\"color: #d73a49\">=<\/span><span style=\"color: #690\">\"vault:v1:cZNHVx+sxdMErXRSuDa1q\/pz49fXTn1PScKfhf+PIZPvy8xKfkytpwKcbC0fF2U=\"<\/span><br># \uff08\u5ba2\u6237\u7aef\uff09\u5bf9\u89e3\u5bc6\u540e\u7684\u6587\u672c\u8fdb\u884cbase64\u89e3\u7801<br>base64 <span style=\"color: #6a737d\">--decode &lt;&lt;&lt; \"NDExMSAxMTExIDExMTEgMTExMQo=\"<\/span><br><br><br># \uff08\u7ba1\u7406\u5458\uff09\u6267\u884c\u5982\u4e0b\u547d\u4ee4\u8fdb\u884c\u5bc6\u94a5\u8f6e\u6362<br>vault write <span style=\"color: #d73a49\">-<\/span>f transit<span style=\"color: #d73a49\">\/<\/span>keys<span style=\"color: #d73a49\">\/<\/span>orders<span style=\"color: #d73a49\">\/<\/span>rotate<br># \uff08\u5ba2\u6237\u7aef\uff09\u518d\u6b21\u8c03\u7528\u52a0\u5bc6\u670d\u52a1\uff0c\u6b64\u65f6\u5bc6\u6587\u5f00\u5934\u4f1a\u53d8\u4e3avault<span>:<\/span>v2<br>vault write transit<span style=\"color: #d73a49\">\/<\/span>encrypt<span style=\"color: #d73a49\">\/<\/span>orders \\<br>    plaintext<span style=\"color: #d73a49\">=<\/span>$<span style=\"color: #997\">(<\/span>base64 <span style=\"color: #d73a49\">&lt;&lt;&lt;<\/span> <span style=\"color: #690\">\"4111 1111 1111 1111\"<\/span><span style=\"color: #997\">)<\/span><br># \uff08\u5ba2\u6237\u7aef\uff09\u4f7f\u7528\u65b0\u5bc6\u94a5\u5305\u88c5\u65e7\u5bc6\u6587\u3002Vault\u4f1a\u81ea\u884c\u5148\u89e3\u5bc6\u518d\u7528\u65b0\u5bc6\u94a5\u52a0\u5bc6\u3002<br>vault write transit<span style=\"color: #d73a49\">\/<\/span>rewrap<span style=\"color: #d73a49\">\/<\/span>orders \\<br>    ciphertext<span style=\"color: #d73a49\">=<\/span><span style=\"color: #690\">\"vault:v1:cZNHVx+sxdMErXRSuDa1q\/pz49fXTn1PScKfhf+PIZPvy8xKfkytpwKcbC0fF2U=\"<\/span><br><br># \uff08\u7ba1\u7406\u5458\uff09\u542f\u7528\u5bc6\u94a5\u768424\u5c0f\u65f6\u81ea\u52a8\u8f6e\u6362<br>vault write transit<span style=\"color: #d73a49\">\/<\/span>keys<span style=\"color: #d73a49\">\/<\/span>orders<span style=\"color: #d73a49\">\/<\/span>config \\<br>    auto_rotate_period<span style=\"color: #d73a49\">=<\/span><span style=\"color: #005cc5\">24<\/span>h<br># <span style=\"color: #997\">(<\/span>\u7ba1\u7406\u5458<span style=\"color: #997\">)<\/span> \u67e5\u770b\u5bc6\u94a5\u4fe1\u606f\uff0c\u5176\u4e2d auto_rotate_period \u4e3a\u8f6e\u6362\u8bbe\u7f6e\uff0c\u9ed8\u8ba4\u503c0s\u8868\u793a\u7981\u7528\u3002    <br>vault read transit<span style=\"color: #d73a49\">\/<\/span>keys<span style=\"color: #d73a49\">\/<\/span>orders<br><br># <span style=\"color: #997\">(<\/span>\u7ba1\u7406\u5458<span style=\"color: #997\">)<\/span> \u8bbe\u7f6e\u6700\u5c0f\u53ef\u89e3\u5bc6\u5bc6\u94a5\u7248\u672c\uff0c\u9ed8\u8ba4\u4ece1\u5f00\u59cb\u6240\u6709\u7248\u672c\u7684\u5bc6\u94a5\u5747\u53ef\u4ee5\u89e3\u5bc6<br>vault write transit<span style=\"color: #d73a49\">\/<\/span>keys<span style=\"color: #d73a49\">\/<\/span>orders<span style=\"color: #d73a49\">\/<\/span>config \\<br>    min_decryption_version<span style=\"color: #d73a49\">=<\/span><span style=\"color: #005cc5\">5<\/span><br><br># \uff08\u7ba1\u7406\u5458\uff09\u5bfc\u51fa\u5bc6\u94a5\uff08\u5305\u62ec\u660e\u6587\u548c\u5bc6\u6587\uff09\uff0c\u5bc6\u6587\u53ef\u4ee5\u4fdd\u5b58\u5230Vault\u7684\u952e\u503c\u5f15\u64ce\uff0c<br>#     \u7528\u4e8e\u5728Vault\u5916\u5bf9\u5927\u6587\u4ef6\u8fdb\u884c\u52a0\u89e3\u5bc6<br>vault write <span style=\"color: #d73a49\">-<\/span>f transit<span style=\"color: #d73a49\">\/<\/span>datakey<span style=\"color: #d73a49\">\/<\/span>plaintext<span style=\"color: #d73a49\">\/<\/span>orders<br><br># \uff08\u7ba1\u7406\u5458\uff09\u5bfc\u5165\u4e00\u4e2a\u5df2\u6709\u7684\u5916\u90e8\u5bc6\u94a5<br>vault read <span style=\"color: #d73a49\">-<\/span>field<span style=\"color: #d73a49\">=<\/span>public_key transit<span style=\"color: #d73a49\">\/<\/span>wrapping_key<\/pre>\n<h3>\u4f7f\u7528\u6570\u636e\u5e93\u5f15\u64ce\u83b7\u5f97\u52a8\u6001\u51ed\u8bc1<\/h3>\n<p style=\"text-align: justify\">\u4ee5\u4e0b\u6f14\u793a\u4f7f\u7528Vault\u7684\u6570\u636e\u5e93\u5f15\u64ce\u6765\u7ba1\u7406\u6570\u636e\u5e93\u8bbf\u95ee\u51ed\u8bc1\uff0c\u6d89\u53ca\u7ba1\u7406\u5458\u548c\u5e94\u7528\u7a0b\u5e8f\u4e24\u4e2a\u89d2\u8272\u3002<\/p>\n<pre># \u9996\u5148\u505a\u4e00\u4e9b\u51c6\u5907\u5de5\u4f5c\uff0c\u672c\u4f8b\u4e2d\u4f7f\u7528docker\u65b9\u5f0f\u542f\u52a8\u4e00\u4e2apostgres\u6570\u636e\u5e93\u5b9e\u4f8b<br><br># \u62c9\u53d6postgres\u7684docker\u955c\u50cf<br>docker pull postgres<span>:<\/span>latest<br># \u542f\u52a8 postgres \u5bb9\u5668<br>docker run \\<br>    <span style=\"color: #6a737d\">--detach \\<\/span><br>    <span style=\"color: #6a737d\">--name learn-postgres \\<\/span><br>    <span style=\"color: #d73a49\">-<\/span>e POSTGRES_USER<span style=\"color: #d73a49\">=<\/span>root \\<br>    <span style=\"color: #d73a49\">-<\/span>e POSTGRES_PASSWORD<span style=\"color: #d73a49\">=<\/span>rootpassword \\<br>    <span style=\"color: #d73a49\">-<\/span>p <span style=\"color: #005cc5\">5432<\/span><span>:<\/span><span style=\"color: #005cc5\">5432<\/span> \\<br>    <span style=\"color: #6a737d\">--rm \\<\/span><br>    postgres<br><br># \u901a\u8fc7docker\u5728\u540d\u4e3alearn<span style=\"color: #d73a49\">-<\/span>postgres\u7684\u5bb9\u5668\u4e2d\u6267\u884cpsql\u547d\u4ee4\uff0c<br># \u6765\u521b\u5efa\u4e00\u4e2a\u540d\u4e3a ro \u7684\u89d2\u8272\uff0c\u7528\u4e8e\u5b8c\u6210\u793a\u4f8b<br>docker exec <span style=\"color: #d73a49\">-<\/span>i \\<br>    learn<span style=\"color: #d73a49\">-<\/span>postgres \\<br>    psql <span style=\"color: #d73a49\">-<\/span>U root <span style=\"color: #d73a49\">-<\/span>c <span style=\"color: #690\">\"CREATE ROLE \\\"ro\\\" NOINHERIT;\"<\/span><br># \u4e3a ro \u89d2\u8272\u6388\u4e88\u4e00\u4e9b\u6743\u9650<br>docker exec <span style=\"color: #d73a49\">-<\/span>i \\<br>    learn<span style=\"color: #d73a49\">-<\/span>postgres \\<br>    psql <span style=\"color: #d73a49\">-<\/span>U root <span style=\"color: #d73a49\">-<\/span>c <span style=\"color: #690\">\"GRANT SELECT ON ALL TABLES IN SCHEMA public TO \\\"ro\\\";\"<\/span><br><br>#<span style=\"color: #6a737d\">--------\u4ee5\u4e0b\u8fdb\u5165\u6b63\u5f0f\u73af\u8282-----<\/span><br># \uff08\u7ba1\u7406\u5458\uff09\u4ee5dev\u6a21\u5f0f\u542f\u52a8\u4e00\u4e2aVault\u670d\u52a1\uff0c\u65b9\u4fbf\u6f14\u793a<br>vault server <span style=\"color: #d73a49\">-<\/span>dev <span style=\"color: #d73a49\">-<\/span>dev<span style=\"color: #d73a49\">-<\/span>root<span style=\"color: #d73a49\">-<\/span>token<span style=\"color: #d73a49\">-<\/span>id root<br># \uff08\u7ba1\u7406\u5458\uff09\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf\uff0c\u65b9\u4fbf\u540e\u7eed\u64cd\u4f5c<br>export VAULT_ADDR<span style=\"color: #d73a49\">=<\/span>http<span>:<\/span><span style=\"color: #d73a49\">\/\/<\/span><span style=\"color: #005cc5\">127.0<\/span><span style=\"color: #005cc5\">.0<\/span><span style=\"color: #005cc5\">.1<\/span><span>:<\/span><span style=\"color: #005cc5\">8200<\/span><br>export VAULT_TOKEN<span style=\"color: #d73a49\">=<\/span>root<br>export POSTGRES_URL<span style=\"color: #d73a49\">=<\/span><span style=\"color: #005cc5\">127.0<\/span><span style=\"color: #005cc5\">.0<\/span><span style=\"color: #005cc5\">.1<\/span><span>:<\/span><span style=\"color: #005cc5\">5432<\/span><br><br># \uff08\u7ba1\u7406\u5458\uff09\u5728Vault\u4e2d\u542f\u7528\u6570\u636e\u5e93\u5f15\u64ce<br>vault secrets enable database<br># \uff08\u7ba1\u7406\u5458\uff09 \u914d\u7f6e postgreql<span style=\"color: #d73a49\">-<\/span>database<span style=\"color: #d73a49\">-<\/span>plugin\uff0c\u5305\u62ec\u8fde\u63a5\u4fe1\u606f<br># connection_url\u652f\u6301\u4ee5<span>,<\/span>\u5206\u5272\u7684\u591a\u4e2a\u5b9e\u4f8b\uff0c\u63d2\u4ef6\u5c06\u4f9d\u6b21\u5c1d\u8bd5\u8fde\u63a5<br>vault write database<span style=\"color: #d73a49\">\/<\/span>config<span style=\"color: #d73a49\">\/<\/span>postgresql \\<br>     plugin_name<span style=\"color: #d73a49\">=<\/span>postgresql<span style=\"color: #d73a49\">-<\/span>database<span style=\"color: #d73a49\">-<\/span>plugin \\<br>     connection_url<span style=\"color: #d73a49\">=<\/span><span style=\"color: #690\">\"postgresql:\/\/{{username}}:{{password}}@$POSTGRES_URL\/postgres?sslmode=disable\"<\/span> \\<br>     allowed_roles<span style=\"color: #d73a49\">=<\/span>readonly \\<br>     username<span style=\"color: #d73a49\">=<\/span><span style=\"color: #690\">\"root\"<\/span> \\<br>     password<span style=\"color: #d73a49\">=<\/span><span style=\"color: #690\">\"rootpassword\"<\/span><br><br># \uff08\u7ba1\u7406\u5458\uff09\u521b\u5efa\u4e00\u4e2a\u53ef\u5728postgres\u4e2d\u5efa\u7acb\u89d2\u8272\u7684sql\u6a21\u677f<br>tee readonly<span style=\"color: #005cc5\">.sql<\/span> <span style=\"color: #d73a49\">&lt;&lt;<\/span>EOF<br><span style=\"color: #d73a49\">CREATE<\/span> ROLE <span style=\"color: #690\">\"{{name}}\"<\/span> WITH LOGIN PASSWORD <span style=\"color: #690\">'{{password}}'<\/span> VALID UNTIL <span style=\"color: #690\">'{{expiration}}'<\/span> INHERIT<span>;<\/span><br>GRANT ro TO <span style=\"color: #690\">\"{{name}}\"<\/span><span>;<\/span><br>EOF<br># \uff08\u7ba1\u7406\u5458\uff09\u521b\u5efa\u540d\u4e3areadonly\u7684\u6570\u636e\u5e93\u89d2\u8272\uff0c\u521b\u5efa\u8bed\u53e5\u5c06\u4f7f\u7528\u4e0a\u9762\u7684sql\u6a21\u677f<br>vault write database<span style=\"color: #d73a49\">\/<\/span>roles<span style=\"color: #d73a49\">\/<\/span>readonly \\<br>      db_name<span style=\"color: #d73a49\">=<\/span>postgresql \\<br>      creation_statements<span style=\"color: #d73a49\">=<\/span>@readonly<span style=\"color: #005cc5\">.sql<\/span> \\<br>      default_ttl<span style=\"color: #d73a49\">=<\/span><span style=\"color: #005cc5\">1<\/span>h \\<br>      max_ttl<span style=\"color: #d73a49\">=<\/span><span style=\"color: #005cc5\">24<\/span>h<br><br># <span style=\"color: #997\">(<\/span>\u5e94\u7528\u7a0b\u5e8f<span style=\"color: #997\">)<\/span> \u4eceVault\u83b7\u53d6\u4e00\u4e2a\u53ea\u8bfb\u89d2\u8272<br># \u8fd4\u56de\u7ed3\u679c\u4e2d\u5305\u62ecusername\u3001password\uff0c\u4ee5\u53ca\u79df\u7ea6id\u548c\u79df\u671f\u7b49\u4fe1\u606f<br>vault read database<span style=\"color: #d73a49\">\/<\/span>creds<span style=\"color: #d73a49\">\/<\/span>readonly<br><br># \u53ef\u4f7f\u7528\u5982\u4e0b\u547d\u4ee4\u9a8c\u8bc1\u83b7\u5f97\u7684\u89d2\u8272\u662f\u5426\u5b58\u5728<br>docker exec <span style=\"color: #d73a49\">-<\/span>i \\<br>    learn<span style=\"color: #d73a49\">-<\/span>postgres \\<br>    psql <span style=\"color: #d73a49\">-<\/span>U root <span style=\"color: #d73a49\">-<\/span>c <span style=\"color: #690\">\"SELECT usename, valuntil FROM pg_user;\"<\/span><br><br><br># \uff08\u7ba1\u7406\u5458\uff09\u5217\u51fa\u6240\u6709\u79df\u7ea6<br>vault list sys<span style=\"color: #d73a49\">\/<\/span>leases<span style=\"color: #d73a49\">\/<\/span>lookup<span style=\"color: #d73a49\">\/<\/span>database<span style=\"color: #d73a49\">\/<\/span>creds<span style=\"color: #d73a49\">\/<\/span>readonly<br>#\uff08\u7ba1\u7406\u5458\uff09\u4f7f\u7528\u73af\u5883\u53d8\u91cf\u4fdd\u5b58\u7b2c\u4e00\u4efd\u79df\u7ea6\u7684id<br>LEASE_ID<span style=\"color: #d73a49\">=<\/span>$<span style=\"color: #997\">(<\/span>vault list <span style=\"color: #d73a49\">-<\/span>format<span style=\"color: #d73a49\">=<\/span>json sys<span style=\"color: #d73a49\">\/<\/span>leases<span style=\"color: #d73a49\">\/<\/span>lookup<span style=\"color: #d73a49\">\/<\/span>database<span style=\"color: #d73a49\">\/<\/span>creds<span style=\"color: #d73a49\">\/<\/span>readonly <span style=\"color: #d73a49\">|<\/span> jq <span style=\"color: #d73a49\">-<\/span>r <span style=\"color: #690\">\".[0]\"<\/span><span style=\"color: #997\">)<\/span><br># \uff08\u7ba1\u7406\u5458\uff09\u7eed\u7ea6<br>vault lease renew database<span style=\"color: #d73a49\">\/<\/span>creds<span style=\"color: #d73a49\">\/<\/span>readonly<span style=\"color: #d73a49\">\/<\/span>$LEASE_ID<br># \uff08\u7ba1\u7406\u5458\uff09\u5728\u79df\u7ea6\u5230\u671f\u524d\u4e3b\u52a8\u64a4\u9500<br>vault lease revoke database<span style=\"color: #d73a49\">\/<\/span>creds<span style=\"color: #d73a49\">\/<\/span>readonly<span style=\"color: #d73a49\">\/<\/span>$LEASE_ID<br># \uff08\u7ba1\u7406\u5458\uff09\u6309\u7167\u524d\u7f00\u64a4\u9500\u6240\u6709\u7b26\u5408\u6761\u4ef6\u7684\u79df\u7ea6<br>vault lease revoke <span style=\"color: #d73a49\">-<\/span>prefix database<span style=\"color: #d73a49\">\/<\/span>creds<span style=\"color: #d73a49\">\/<\/span>readonly<\/pre>\n<p style=\"text-align: justify\">Vault\u8fd8\u63d0\u4f9b\u6570\u636e\u5e93\u7528\u6237\u540d\u6a21\u677f\u3001\u5bc6\u7801\u7b56\u7565\u7b49\u529f\u80fd\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u662f\u4ec0\u4e48 HashiCorp Vault \u662f\u4e00\u4e2a\u7528\u4e8e\u7ba1\u7406\u5bc6\u7801\u3001\u5bc6\u94a5\u548c\u8bc1\u4e66\u7b49\u79d8\u5bc6\u7684\u7cfb\u7edf\uff0c\u540c\u65f6\u8fd8\u53ef\u63d0\u4f9b\u6709\u8eab\u4efd\u8ba4\u8bc1\u548c\u6388 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":251715,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[202645],"tags":[],"class_list":["post-251714","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-202645"],"_links":{"self":[{"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/posts\/251714","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/comments?post=251714"}],"version-history":[{"count":0,"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/posts\/251714\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/media\/251715"}],"wp:attachment":[{"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/media?parent=251714"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/categories?post=251714"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/tags?post=251714"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}