Spring application and Vault in docker-compose: how to init vault server?

Viewed 267

I'm working on an application that should get some secrets from Vault. I want the app to run on a container and the vault server on another one. However I'm having some issues putting things together with docker-compose.

services:
   app:
       image: app/progettinotoy
       networks:
           - mainnet
       ports:
           - 8080:8080
       depends_on:
           - "vault"
           
       vault:
       image: vault
       cap_add:
           - "IPC_LOCK"
       networks:
           - mainnet
       ports:
           - 8200:8200
       environment: 
           VAULT_ADDR: http://127.0.0.1:8200
           VAULT_LOCAL_CONFIG:
               api_addr = "http://127.0.0.1:8200"
               cluster_addr = "https://127.0.0.1:8201"
               ui = true

               backend "file" {
                 path    = "/vault/file"
               }

               listener "tcp" {
                 address     = "0.0.0.0:8200"
                 tls_disable = "true"
               }
       command: 
           - "server"
        
   
networks:
   mainnet:
       driver: bridge        

The main reason is that even though vault server is running, I should execute vault operator init and get root token and unseal keys before application starts to interact with vault server. How can i do that?

1 Answers

The answer depends on what happens to the data stored on /vault/file.

If the data is persistent (will it survive a restart)? If so, you should deploy Vault on its own and do a proper initialization ceremony.

If not (like an ephemeral test instance), run Vault in DEV mode with server -dev --dev-root-token-id=asdf, it will use asdf as the root token.

Related