marinakr

marinakr

Vault configuration best practice

Hi Friends,
I am about using libvault to read DATABASE_URL and other secrets.
I m going to use Vault.Auth.Kubernetes
I am not sure I am following mix release guide and ConfigProvider
Should I define a module VaultConfigProvider with codes like

def init(vault_config) when is_list(vault_config) do
    vault_config
  end

  def load(config, vault_config) do
    # We need to start any app we may depend on.
    {:ok, _} = Application.ensure_all_started(:jason)

    {:ok, vault} =
      Vault.new(
        engine: Vault.Engine.KVV2,
        auth: Vault.Auth.Kubernetes,
        http: Vault.HTTP.Tesla,
        host: host
      )
      |> Vault.auth(%{role: role, jwt: jwt})

{:ok,
 %{
   "SECRET_KEY_BASE" => "..",
   "DATABASE_URL" => "ecto://dbhost:5432/.."
 } = json} = Vault.read(vault, "myapp/env")

Config.Reader.merge(
      config,
      my_app: [
        some_value: json["DATABASE_URL"],
        another_value: json["DATABASE_URL"],
      ]
    )

and then remove all lines that get system env from releases.exs?
Is there the easiest way to get the vault secrets?

Where is the best place to define vault_config_provider.ex?

Marked As Solved

marinakr

marinakr

So I decided to use runtime. exs in mix release

config/runtime.exs now looks like:

import Config

if config_env() == :prod do
{:ok, _} = Application.ensure_all_started(:jason)
{:ok, _} = Application.ensure_all_started(:hackney)

jwt =
  System.get_env("JWT_TOKEN_PATH")
  |> Kernel.||("/var/run/secrets/kubernetes.io/serviceaccount/token")
  |> File.read!()

vault_host = System.fetch_env!("VAULT_ADDR")
vault_k8s_role = System.fetch_env!("VAULT_K8S_ROLE")
vault_prefix = System.fetch_env!("VAULT_PREFIX")
vault_env_path = System.get_env("VAULT_ENV_PATH") || "secrets"

{:ok, vault} =
  Vault.new(
    engine: Vault.Engine.KVV2,
    auth: Vault.Auth.Kubernetes,
    http: Vault.HTTP.Tesla,
    host: vault_host
  )
  |> Vault.auth(%{role: vault_k8s_role, jwt: jwt})

{:ok, vault_secrets} = Vault.read(vault, "#{vault_prefix}/#{vault_env_path}")

################################################################################
## Release Config (with Vault secrets)
################################################################################
config :myapp, MS.Repo,
  # ssl: true,
  url: Map.fetch!(vault_secrets, "DATABASE_URL"),
  pool_size: String.to_integer(vault_secrets["POOL_SIZE"]) || 10
...
end

and to include runtime.exs on release start runtime_config_path should be added to mix.exs:

  releases: [
        myapp_web: [
          runtime_config_path: "config/runtime.exs",
          version: "0.0.1",
          applications: [
            myapp_web: :permanent
            ...

So no additional config readers were used

Last Post!

Aktaeon

Aktaeon

Thank you for sharing the code Marina. I think it mostly similar to what I had in mind when I asked the question and likely will fallback on this definitely a good answer.

I have rewritten my solution as a configprovider with the idea of using an agent for vault to do later dynamic secrets and updates of tokens, but I am seeing the currently my configprovider is not starting with a simple iex -S mix phx.server only when doing a full release.

Where Next?

Popular in Questions Top

hariharasudhan94
lets say i have a sample like a = 20; b = 10; if (a > b) do {:ok, "a"} end if (a < b) do {:ok, b} end if (a == b) do {:ok, "equa...
New
jononomo
For some reason my phoenix channels are working for me in my local dev environment, but as soon as I deploy via Docker, I get a 403 error...
New
Lily
In templates/appointment/index.html.eex: <%= for appointment <- @appointments do %> <tr> <td><%= appoi...
New
aadeshere1
I have a another noob question about loop. Since elixir is immutable, while loop is not directly possible. total = 10 while total != 0 ...
New
Fl4m3Ph03n1x
About me? ( if you have nothing better to do than reading about some random guy in the internet :stuck_out_tongue: ) Hello all, this is ...
New
shijith.k
I am trying to start a new phoenix project with elixir 1.9, but mix phx.new does not work. It says that ** (Mix) The task "phx.new" could...
New
stefanluptak
Hello everybody, usually, I use a 29" ultra-wide monitor for VSCode which can easily accomodate explorer (files panel) + file with code ...
New

Other popular topics Top

openscript
Hello! Sorry for this astonishing simple question, but I’m really stuck. I try to set up the intellij-elixir plugin, but I don’t know ho...
New
joeerl
Hello again - after a longish gap I’ve decided I really must dig into Elixir and see what’s been happening here - so I have a few questio...
New
greenz1
I have a phoenix application from which a user can download multiple(5-6) files of size 1MB. I couldn’t find anything related to sending ...
New
shijith.k
I am trying to start a new phoenix project with elixir 1.9, but mix phx.new does not work. It says that ** (Mix) The task "phx.new" could...
New
Patoshizzle
After calling mix ecto.create I get this error: 17:00:32.162 [error] GenServer #PID<0.412.0> terminating ** (Postgrex.Error) FATAL...
New
sergio
Kind of like when jquery came out, it was super necessary. Existing drag and drop libraries have a bunch of baggage to support old browse...
New

We're in Beta

About us Mission Statement