Allow configuration of AWS-EC2 nonce.

We now support static configuration of the AWS-EC2 authentication nonce to support re-login on application crashes/vm-internal restarts.

Closes gh-103.
This commit is contained in:
Mark Paluch
2017-05-11 17:00:52 +02:00
parent c04c6e994d
commit 03dd5e36c0
3 changed files with 20 additions and 14 deletions

View File

@@ -240,17 +240,7 @@ party does not have the nonce and can raise an alert in Vault for
further investigation.
The nonce is kept in memory and is lost during application restart.
.bootstrap.yml with disabled nonce
====
[source,yaml]
----
spring.cloud.vault:
authentication: AWS_EC2
aws-ec2:
use-nonce: false
----
====
You can configure a static nonce with `spring.cloud.vault.aws-ec2.nonce`.
AWS-EC2 authentication roles are optional and default to the AMI.
You can configure the authentication role by setting the
@@ -277,7 +267,7 @@ spring.cloud.vault:
role: application-server
aws-ec2-path: aws-ec2
identity-document: http://...
use-nonce: false
nonce: my-static-nonce
----
====
@@ -286,7 +276,7 @@ authentication method
* `role` sets the role name of the AWS EC2 role definition
* `aws-ec2-path` sets the path of the AWS EC2 mount to use
* `identity-document` sets URL of the PKCS#7 AWS EC2 identity document
* `use-nonce` setting this value to `false` will disable nonce usage
* `nonce` used for AWS-EC2 authentication. An empty nonce defaults to nonce generation
See also: https://www.vaultproject.io/docs/auth/aws-ec2.html[Vault Documentation: Using the aws-ec2 auth backend]

View File

@@ -45,6 +45,7 @@ import org.springframework.vault.authentication.AppRoleAuthentication;
import org.springframework.vault.authentication.AppRoleAuthenticationOptions;
import org.springframework.vault.authentication.AwsEc2Authentication;
import org.springframework.vault.authentication.AwsEc2AuthenticationOptions;
import org.springframework.vault.authentication.AwsEc2AuthenticationOptions.Nonce;
import org.springframework.vault.authentication.ClientAuthentication;
import org.springframework.vault.authentication.ClientCertificateAuthentication;
import org.springframework.vault.authentication.CubbyholeAuthentication;
@@ -360,9 +361,13 @@ public class VaultBootstrapConfiguration implements InitializingBean {
VaultProperties.AwsEc2Properties awsEc2 = vaultProperties.getAwsEc2();
Nonce nonce = StringUtils.hasText(awsEc2.getNonce())
? Nonce.provided(awsEc2.getNonce().toCharArray()) : Nonce.generated();
AwsEc2AuthenticationOptions authenticationOptions = AwsEc2AuthenticationOptions
.builder().role(awsEc2.getRole()) //
.path(awsEc2.getAwsEc2Path()) //
.nonce(nonce) //
.identityDocumentUri(URI.create(awsEc2.getIdentityDocument())) //
.build();

View File

@@ -13,15 +13,16 @@
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.springframework.cloud.vault.config;
import lombok.Data;
import lombok.Getter;
import org.hibernate.validator.constraints.NotEmpty;
import org.hibernate.validator.constraints.Range;
import org.springframework.boot.bind.RelaxedPropertyResolver;
import org.springframework.boot.context.properties.ConfigurationProperties;
import org.springframework.boot.context.properties.DeprecatedConfigurationProperty;
import org.springframework.context.EnvironmentAware;
import org.springframework.core.env.Environment;
import org.springframework.core.io.Resource;
@@ -184,8 +185,18 @@ public class VaultProperties implements EnvironmentAware {
/**
* Flag whether to generate and send a nonce.
*
* @deprecated not used, will be removed in a future version.
*/
@Getter(onMethod = @__(@DeprecatedConfigurationProperty(reason = "not used")))
@Deprecated
private boolean useNonce = true;
/**
* Nonce used for AWS-EC2 authentication. An empty nonce defaults to nonce
* generation.
*/
private String nonce;
}
@Data