ceph-csi/examples/kms/vault/tenant-sa.yaml
Niels de Vos d941e5abac util: make parseTenantConfig() usable for modular KMSs
parseTenantConfig() only allowed configuring a defined set of options,
and KMSs were not able to re-use the implementation. Now, the function
parses the ConfigMap from the Tenants Namespace and returns a map with
options that the KMS supports.

The map that parseTenantConfig() returns can be inspected by the KMS,
and applied to the vaultTenantConnection type by calling parseConfig().

Signed-off-by: Niels de Vos <ndevos@redhat.com>
2021-07-13 17:16:35 +00:00

24 lines
551 B
YAML

---
#
# The ServiceAccount "ceph-csi-vault-sa" should be created in the Namespace of
# the tenant that will be creating encrypted PVCs with a "vaulttenantsa" KMS
# provider.
#
apiVersion: v1
kind: ServiceAccount
metadata:
name: ceph-csi-vault-sa
---
#
# Each tenant most likely has their own VAULT_BACKEND_PATH or other
# configuration options. In this example, the tenant has its own key-value
# store at "tenant".
#
apiVersion: v1
kind: ConfigMap
metadata:
name: ceph-csi-kms-config
data:
vaultBackendPath: tenant
vaultRole: ceph-csi-tenant