refactor(vault): disable Vault HA

Still need manual unseal after rolling upgrade anyway
This commit is contained in:
Khue Doan 2022-05-08 22:10:55 +07:00
parent 4676650f59
commit 683282cd76

View File

@ -2,47 +2,6 @@ vault:
injector: injector:
enabled: false enabled: false
server: server:
# TODO enable TLS?
ha:
enabled: true
replicas: 3
raft:
enabled: true
setNodeId: true
config: |
ui = true
listener "tcp" {
tls_disable = 1
address = "[::]:8200"
cluster_address = "[::]:8201"
}
storage "raft" {
path = "/vault/data"
retry_join {
leader_api_addr = "http://vault-0.vault-internal:8200"
}
retry_join {
leader_api_addr = "http://vault-1.vault-internal:8200"
}
retry_join {
leader_api_addr = "http://vault-2.vault-internal:8200"
}
autopilot {
cleanup_dead_servers = "true"
last_contact_threshold = "200ms"
last_contact_failure_threshold = "10m"
max_trailing_logs = 250000
min_quorum = 3
server_stabilization_time = "10s"
}
}
service_registration "kubernetes" {}
dataStorage: dataStorage:
storageClass: longhorn storageClass: longhorn
ingress: ingress: