nrec-ansible/project/roles/vault/templates/vault.service.j2
Torjus Håkestad bd07d4ed2c
All checks were successful
ci/woodpecker/push/woodpecker Pipeline was successful
Update vault listener address
2022-01-11 16:29:17 +01:00

29 lines
1004 B
Django/Jinja

[Unit]
Description=Vault Container
After=docker.service
After=dockerdata.mount
Requires=docker.service
Requires=dockerdata.mount
[Service]
TimeoutStartSec=0
Restart=always
ExecStartPre=-/usr/bin/docker stop vault
ExecStartPre=-/usr/bin/docker rm vault
ExecStartPre=-/usr/bin/docker pull vault:latest
ExecStart=/usr/bin/docker run \
-e VAULT_DISABLE_MLOCK=true \
-e 'VAULT_LOCAL_CONFIG={"backend": {"file": {"path": "/vault/file"}}, {"listener": [{"tcp":{"address": "0.0.0.0:8200"}, "default_lease_ttl": "168h", "max_lease_ttl": "720h", "ui": "true"}' \
-e "VAULT_API_ADDR=https://vault.t-juice.club" \
-l "traefik.enable=true" \
-l "traefik.http.routers.vault.rule=Host(`vault.t-juice.club`)" \
-l "traefik.http.routers.vault.tls=true" \
-l "traefik.http.routers.vault.tls.certresolver=le" \
-l "traefik.http.services.vault.loadbalancer.server.port=8200" \
-v /dockerdata/vault:/vault/file \
--network proxy \
--name vault vault:latest server
[Install]
WantedBy=multi-user.target