deltamir.ansible_hashistack
Ansible-Hashistack
This role leverage the ansible-consul, ansible-nomad and ansible-vault roles to deploy Consul, Nomad and Vault clusters in a simple, secure and flexible way
Why simple ?
For starter, it's one role and not three...
And this role use sanes defaults in order to provide an easy configuration with only a handful mandatory variables. See the examples.
Contrary to the aforementioned roles, we provide a container that can be use to deploy your clusters manually or be integrated in a CD.
Lastly this role automatically configure interoperability between the 3 products :
- The Vault cluster is backed by the Consul cluster
- The Nomad cluster is Consul-enabled to allow service registration of jobs
- The Nomad cluster is integrated with Vault to introduce secrets to jobs
- Vault and Nomad are themselve registered in Consul to make use of Intents
- Vault is configured to manage Consul and Nomad ACLs through the dedicated Secret Engines TODO
Why secure ?
This role is not a simple merge between three existing community-supported projects. On top of thoses, it will configure as well :
- Automatic Gossip Key rotation with user-defined interval for both Nomad and Consul clusters leveraging a consul-template nomad job.
- PKI management for Consul, Nomad and Vault with individual certificates for each binary and each node in order to achieve full mTLS across clusters
- Automatic mTLS Certificate Key rotation with user-defined interval for Nomad, Consul and Vault leveraging a consul-template systemd service per node
- Vault auto-unseal with Transit Secret Engine against a master Vault configured by this role
- Cross ACL management for Consul and Nomad using Vault's secret providers (TODO)
Why flexible ?
The amazing configurability provided by ansible-consul,
ansible-nomad and
ansible-vault through their variables is not overrided by our role.
This way you can configure and adjust your clusters to your needs with thoses variables. Check the documentations of theses individual roles for more informations.
Requirements
Pip and package dependencies
If not used within our container image, the role have the following dependencies :apt-get install unzip curl pip install ansible-modules-hashivault hvac
Global Vault
In order to configure a PKI, enable automatic rotation of both certificates and gossip key AND unseal your Vault cluster, this role leverage a master Vault.
What is this master Vault ?
It simply is another Hashicorp Vault instance you own :
- Accessible from your cluster
- Accessible from your ansible-enabled deployment host (or the container)
- You have at least the following permissions on this instance :
- TBD
- TBD
What data will I intrust to the master Vault ?
Sensitives ones. This role uses the K/V secret engine to hold the gossip keys, the Transit secret engine with capabilities to unseal you cluster and 3 PKI secret engines with 1 CA signing you mTLS certificates
The master Vault does not need to be populated or configured whatsoever, this role will take care of this for you.
TODO Diagram showing the deployment process with a master Vault
A small HCP Vault instance is a great candidate for this job, but if you won't deploy in a production-ready environment you can as well use a dev instance on your laptop or a small IOT device.
Role Variables
This role have 6 mandatory variables. See the examples.
global_vault_adress
- URL of the master Vault
- Example: http://[hcp_url]:8200
global_vault_token
- Token used to configure the master Vault. Needs create_orphan in order to create child token for the services
- Needs the following permissions : TBD
node_name
- Name of the node as seen by Consul and Nomad
- Setted per-host
- Can be overidden by
consul_node_nameandnomad_node_namefrom parent roles
consul_node_role
- The Consul role of the node, one of: server or client
- Default value: client
- Setted per-host ; Currently tested only with server for all nodes, so be sure to override it
- This role does not support bootstrap like ansible-consul role
nomad_node_role
- The Nomad role of the node, one of: server, client or both
- Default value: client
- Setted per-host ; Currently tested only with both, so be sure to override it
consul_template_version
- Version of the consul_template binary to use
- Check the last release here
consul_version, nomad_version, vault_version
- Theses are not mandatory but are recommended
- The default values are thoses from their respective parent jobs
Examples
Example playbook here :
- name: Assemble Hashistack cluster
hosts: instances
any_errors_fatal: true
become: true
become_user: root
roles:
- {role: ansible_hashistack}
Usage via the container Image :
TODO
docker pull deltamir/ansible-hashistack
Installation from Galaxy
ansible-galaxy install deltamir.ansible_hashistack
License
Author Information
Deltamir - ITN Security Expert, DevSecOps Engineer and Certified Pentester in a Telecom company
Contact via Github inbox
Other
The CI of this project is handled here on Gitlab
This project patch management is handled by a Renovate Bot on Gitlab
This project is mirrored here on Github
A Consul backed Nomad and Consul backed Vault cluster with auto-secret rotation and ACL management
ansible-galaxy install deltamir.ansible_hashistack