!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

171 Members
43 Servers

Load older messages


SenderMessageTime
28 May 2022
@joerg:thalheim.ioMic92 joined the room.11:33:20
@mic92:nixos.devMic92 left the room.11:33:26
29 May 2022
@nospaces:fairydust.spacenospaces joined the room.18:25:14
30 May 2022
@florian:web3.foundation@florian:web3.foundation changed their display name from Florian | OoO -> 29.5. to Florian | W3F.09:04:49
31 May 2022
@joerg:thalheim.ioMic92Wow, reading this I get gnupg vibes: https://support.hashicorp.com/hc/en-us/articles/4407386653843-Vault-KV-V2-Secrets-Engine-Permission-Denied-16:35:35
@joerg:thalheim.ioMic92This is not well-designed.16:35:41
@joerg:thalheim.ioMic92I guess I should have read this here: https://www.vaultproject.io/docs/secrets/kv/kv-v2#acl-rules16:38:26
1 Jun 2022
@tinybronca:sibnsk.net@tinybronca:sibnsk.net joined the room.09:07:10
@joerg:thalheim.ioMic92 grahamc (he/him): are ec2 role tags supported (i.e. created with vault_aws_auth_backend_role_tag) supported by nixos-vault-service 13:38:44
@joerg:thalheim.ioMic92?13:38:45
@grahamc:nixos.org@grahamc:nixos.orgshould be, any auth method that vault agent supports13:39:06
@joerg:thalheim.ioMic92what do you usually use?13:39:53
@joerg:thalheim.ioMic92I have multi-region deployment so those normal iam methods wouldn't work13:40:25
@joerg:thalheim.ioMic92 Turns out I was also using vault_aws_auth_backend_role_tag wrong in terraform but it is also impossible to use because it creates dependency cycles between the ec2 instances I am trying to create. 14:04:43
@joerg:thalheim.ioMic92It also seems that nixos-vault-service cannot be used with aws ec2 auth. Once there are two services that require a secret. The second instance cannot authenticate because of nonce missmatches15:07:52
@grahamc:nixos.org@grahamc:nixos.orgthat is surprising, we use it for aws ec, auth16:59:24
@joerg:thalheim.ioMic92Check out this: https://github.com/DeterminateSystems/nixos-vault-service/issues/5817:19:40
@grahamc:nixos.org@grahamc:nixos.orghum...17:22:11
@joerg:thalheim.ioMic92It was definitly client nonce errors. I had to delete the old onces manually from vault17:22:43
@joerg:thalheim.ioMic92And I also saw the error messages17:22:56
@grahamc:nixos.org@grahamc:nixos.org oh we don't use config.type = "ec2"; because it isn't recommended anymore by hashicorp 17:23:03
@grahamc:nixos.org@grahamc:nixos.orgwe use the type iam17:23:07
@grahamc:nixos.org@grahamc:nixos.orgwe will document the incompatibility17:23:34
@joerg:thalheim.ioMic92Yeah, but iam is simply not usable if you have multiple regions17:23:45
@grahamc:nixos.org@grahamc:nixos.orgno?17:23:51
@grahamc:nixos.org@grahamc:nixos.orghow so?17:23:53
@joerg:thalheim.ioMic92because a role is tight to a single region17:23:57
@grahamc:nixos.org@grahamc:nixos.orgI don't think IAM roles are tied to a region17:24:20
@joerg:thalheim.ioMic92not iam roles17:25:07
@grahamc:nixos.org@grahamc:nixos.orgbut at any rate, it should work across regions without too much work17:25:16

Show newer messages


Back to Room ListRoom Version: 6