HashiCorp Vault Chart Values Reference

This reference lists the HashiCorp Vault values the Axual Governance Helm chart exposes: the image pull secrets, the server ingress, and the data storage class.

Type

Reference

Goal

Look up a HashiCorp Vault chart value while writing the Axual Governance values file.

Audience

Platform Operator deploying the HashiCorp Vault that holds Axual Governance secrets.

When to use

While configuring HashiCorp Vault, alongside the procedure that installs Axual Governance.

Contents

The sections below cover each area in this reference:

About HashiCorp Vault

HashiCorp Vault is an identity-based secrets and encryption management system. In an Axual Platform installation it holds the private keys, certificates and connector credentials that Platform Manager writes and that Axual Connect and Kafka Connect read back at runtime.

HashiCorp Vault Configuration

Axual Governance wraps the official HashiCorp Vault Helm chart under the platform-manager-vault alias, so the HashiCorp public documentation holds the full list of configuration options. The values below are the ones an Axual Governance installation normally sets.

HashiCorp Vault Repository Configuration

You can override imagePullSecrets. If you leave it unset, the Vault pod uses global.imagePullSecrets.

values.yaml
platform-manager-vault:
  global:
    imagePullSecrets:
      - name: axualdockercred

HashiCorp Vault Server Configuration

You can expose the HashiCorp Vault server outside the Kubernetes cluster through an ingress.

values.yaml
platform-manager-vault:
  server:
    ingress:
      enabled: true
      activeService: false
      ingressClassName: ""
      hosts:
        - host: "<hostDomainName>"
          paths:
            - "/"

HashiCorp Vault DataStorage Configuration

You can set the storage class the HashiCorp Vault data store uses.

values.yaml
platform-manager-vault:
  server:
    dataStorage:
      storageClass: "hostpath"