fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

9.8K
active users

#vault

0 posts0 participants0 posts today

....aaaaaand #OpenBao (the fork of #Hashicorp #Vault) is on its way to @opensuse #Tumbleweed in the latest version 2.2.1. Since 2.2.0 the webui is included in OpenBao, so this can be a full replacement for Vault!

Looking forward to doing more testing with it!

In case you want to try it out, here is a #vagrant #libvirt setup using #Ansible to prepare an OpenBao server VM and a client using a secret.
codeberg.org/johanneskastl/ope

Summary card of repository johanneskastl/openbao_vagrant_libvirt_ansible
Codeberg.orgopenbao_vagrant_libvirt_ansibleVagrant-libvirt setup with an OpenBao Server and a client VM running the OpenBao Agent (and a PostgreSQL database)

Dear #AWX users out there (AWX as in Ansible, not AWS as in Amazon...),

does anyone have good pointers on connecting AWX and #Hashicorp #Vault / #OpenBoa **without** having to define each secret/credential again in AWX?

I have set up a basic connection according to the documentation: ansible.readthedocs.io/project
And I have created a credential using that lookup and could successfully output its value in a playbook run in AWX.

But having to define a AWX credential for each secret that I need to pull from Vault/OpenBoa sounds like a lot of unnecessary duplication.
(Yes, I know you can manage AWX via Ansible. We do that already. But still, you need to define the credentials in your code somewhere for the automation to create it in AWX)

ansible.readthedocs.io12. Secret Management System — Ansible AWX community documentation

Uuuuuuuh, #OpenBao (the open source fork of #Hashicorp #Vault) just released version 2.2.0 and now includes the UI, that was missing so far.

The package for @opensuse was adapted, tested and worked out fine. Will soon be available in #Tumbleweed!

If you want to test this out, feel free to use this vagrant-libvirt setup of mine:
codeberg.org/johanneskastl/ope

Summary card of repository johanneskastl/openbao_vagrant_libvirt_ansible
Codeberg.orgopenbao_vagrant_libvirt_ansibleVagrant-libvirt setup with an OpenBao Server and a client VM running the OpenBao Agent (and a PostgreSQL database)

Ups, jetzt habe ich einen #Obsidian #Vault auf meiner Platte... Bin ja mal gespannt! Was jetzt passiert! Todos in Kanban möchte ich probieren... Da hat jemand (ein Journalist) die letzten Tag drüber getrötet... Er trackt seine ca 20 monatlichen Texte bis hin zur bezahlten Rechnung darüber.

It would be great if Cryptomator some day becomes Wayland native.

Currently it only supports Xorg and that hasn't got the security I need.

So for now I will continue to create LUKS vaults and upload them to the cloud.
One downside is that I have to decide the size of the vault beforehand.
Another downside is that I can only open the vault on Linux.

But I'm pretty confident in the security it provides.

#Cryptomator #LUKS #Linux #Security #Encryption #CloudStorage. #Vault #Wayland #Xorg

Наш путь delivery of secrets: как мы пришли к связке Bank-Vaults и Vault Secret Operator

Привет, Хабр! Меня зовут Натиг Нагиев, я Devops-инженер в МТС Диджитал. На нашем проекте мы обеспечиваем авторизацию внешних клиентов в продуктах МТС. Это Mission Critical система, где мы оптимизировали и гарантировали доставку секретов в контейнеры с микросервисом, избавлялись от дополнительных рабочих нагрузок и исключали внешние зависимости. В прошлом материале я сравнил разные инструменты, которые мы перебрали, а в этом расскажу про наше итоговое решение — связку Bank-Vaults и Vault Secrets Operator.

habr.com/ru/companies/ru_mts/a

ХабрНаш путь delivery of secrets: как мы пришли к связке Bank-Vaults и Vault Secret OperatorПривет, Хабр! Меня зовут Натиг Нагиев, я Devops-инженер в МТС Диджитал. На нашем проекте мы обеспечиваем авторизацию внешних клиентов в продуктах МТС. Это Mission Critical система, где мы...
Continued thread

#JavaScript #Java #Flutter #Angular #Rust #GitOps #Kafka #HashiCorp #AI #ChatGPT #DevOps #Terraform #Consul #Vault #Nomad #RAG #GameDev #Unity #UnrealEngine #WebDev #Cloud #REST #API #Go #Python #Kubernetes #Docker #TypeScript #React #NodeJS #Spring

🗓️ Next week's highlights:
Feb 4: Game Dev Stockholm #5 (Waterfront Congress Centre)
Feb 4: Jforum #122 - Java Next and multimodal RAG (Waterfront Congress Centre)
Feb 5: Simplify and Secure: The Future of Infrastructure and hashtag#DevOps