Skip to main content

Vault as the platform's shared secrets store

· One min read
Arpan Mandal

devops-server-deployer, devops-server-onboarding, and application-deployer read their secrets from one mTLS-secured Vault KV store. vault-deployer deploys that store, so it takes its secrets from the environment instead. Nothing secret is committed to a repo.

Each of those repos needs five values to reach Vault: VAULT_API_ENDPOINT, VAULT_API_KEY, and three base64-encoded PEM values for the CA certificate, client certificate, and client key. The three PEM values are decoded to temporary files at runtime.

Vault paths are scoped by CS_PROJECT_CODE, which is mandatory wherever it appears. An internal Root CA, also stored in Vault, signs every internal TLS certificate, including the PostgreSQL server and client certificates.