Vault as the platform's shared secrets store
· One min read
devops-server-deployer, devops-server-onboarding, and application-deployer read their secrets
from one mTLS-secured Vault KV store. vault-deployer deploys that store, so it takes its secrets from
the environment instead. Nothing secret is committed to a repo.
Each of those repos needs five values to reach Vault: VAULT_API_ENDPOINT, VAULT_API_KEY, and three
base64-encoded PEM values for the CA certificate, client certificate, and client key. The three PEM
values are decoded to temporary files at runtime.
Vault paths are scoped by CS_PROJECT_CODE, which is mandatory wherever it appears. An internal Root
CA, also stored in Vault, signs every internal TLS certificate, including the PostgreSQL server and
client certificates.