data:image/s3,"s3://crabby-images/195b6/195b67b9e3450a8c80eb1641d6af8162b8ab8fd0" alt="image-20230304125220402"
2024. 9. 9.약 17 분
jenkins와 vault otp를 연동하여 pipe line에서 ssh/scp test
# ssh 권한을 사용 할 policy 생성
$ tee ssh-policy.hcl <<EOF
# To list SSH secrets paths
path "ssh/*" {
capabilities = [ "list" ]
}
# To use the configured SSH secrets engine otp_key_role role
path "ssh/creds/otp_key_role" {
capabilities = ["create", "read", "update"]
}
EOF
#ssh(otp) 정책 생성
$ vault policy write ssh ssh-policy.hcl
#rest api에서 사용 할 token 생성
$ vault token create -policy=ssh