-
Notifications
You must be signed in to change notification settings - Fork 15
/
keywhiz-proxy-env
50 lines (44 loc) · 1.76 KB
/
keywhiz-proxy-env
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
# Default Secrets and Log directory
# ---------------------------------
SECRETS_DIR=/secrets
LOGGING_PATH=/log
# Keywhiz Proxy Server config
# ---------------------------
SERVER_SSL_KEY_STORE=file:${SECRETS_DIR}/keywhiz_proxy_keystore.p12
SERVER_SSL_KEY_PASSWORD=xxxxx
SERVER_SSL_KEY_STORE_PASSWORD=xxxxx
# Keywhiz Server and Automation Client config
# -------------------------------------------
ONEOPS_KEYWHIZ_BASE_URL=https://keywhiz.com:4444/
ONEOPS_KEYWHIZ_TRUST_STORE_PATH=file:${SECRETS_DIR}/keywhiz_truststore.p12
ONEOPS_KEYWHIZ_TRUST_STORE_STORE_PASSWORD=xxxxx
ONEOPS_KEYWHIZ_KEY_STORE_PATH=file:${SECRETS_DIR}/keywhiz_keystore.p12
ONEOPS_KEYWHIZ_KEY_STORE_STORE_PASSWORD=xxxxx
ONEOPS_KEYWHIZ_KEY_STORE_KEY_PASSWORD=xxxxx
ONEOPS_KEYWHIZ_SECRET_MAX_SIZE=350000
ONEOPS_KEYWHIZ_CLI_DOWNLOAD_URL=https://secrets.oneops.com/cli/download
ONEOPS_KEYWHIZ_CLI_USER_AGENT_HEADER=OneOpsSecretsCLI-
# AD/LDAP Server Config
# ---------------------
ONEOPS_LDAP_SERVER=ldap://ldap.com
ONEOPS_LDAP_USER_BASE_DN=dc=xxxxx,dc=xxxxx,dc=com
ONEOPS_LDAP_USER_DN=CN=xxxxx,DC=xxxxx,DC=xxxxx,DC=com
ONEOPS_LDAP_PASSWORD=xxxxx
ONEOPS_LDAP_TRUST_STORE_PATH=file:${SECRETS_DIR}/ldap_truststore.p12
ONEOPS_LDAP_TRUST_STORE_STORE_PASSWORD=xxxxx
# Keywhiz Proxy Token Auth Config
# -------------------------------
ONEOPS_AUTH_SIGNING_KEY=xxxxx
ONEOPS_AUTH_EXPIRES_IN_SEC=xxxxx
# OneOps User Datasource config
# -----------------------------
ONEOPS_PROD_DB_URL=jdbc:postgresql://prod-userdb:5432/xxxxx
ONEOPS_MGMT_DB_URL=jdbc:postgresql://mgmt-userdb:5432/xxxxx
ONEOPS_STG_DB_URL=jdbc:postgresql://stg-userdb:5432/xxxxx
ONEOPS_DEV_DB_URL=jdbc:postgresql://dev-userdb:5432/xxxxx
ONEOPS_DB_USER=xxxxxx
ONEOPS_DB_PASS=xxxxxx
# Management app config
# ---------------------
MANAGEMENT_USER=xxxxx
MANAGEMENT_PASSWORD=xxxxx