Skip to content

Instantly share code, notes, and snippets.

@skippy
Last active August 10, 2016 16:25
Show Gist options
  • Save skippy/6d03a95ba1d75408568924693177eb77 to your computer and use it in GitHub Desktop.
Save skippy/6d03a95ba1d75408568924693177eb77 to your computer and use it in GitHub Desktop.
vault 0.6.1-rc2 unseal issues
core@ip-10-0-10-31 ~ $ sudo systemctl restart vault
$ docker exec -it vault vault unseal -ca-cert=/tmp/tmp_ca/ca.cer -address=https://127.0.0.1:8200
Key (will be hidden):
Sealed: true
Key Shares: 5
Key Threshold: 3
Unseal Progress: 1
$ docker exec -it vault vault unseal -ca-cert=/tmp/tmp_ca/ca.cer -address=https://127.0.0.1:8200
Key (will be hidden):
Sealed: true
Key Shares: 5
Key Threshold: 3
Unseal Progress: 2
$ docker exec -it vault vault unseal -ca-cert=/tmp/tmp_ca/ca.cer -address=https://127.0.0.1:8200
Key (will be hidden):
Sealed: false
Key Shares: 5
Key Threshold: 3
Unseal Progress: 0
$ docker exec -it vault vault status -address=https://127.0.0.1:8200
Sealed: false
Key Shares: 5
Key Threshold: 3
Unseal Progress: 0
High-Availability Enabled: true
Mode: standby
Leader: https://10.0.11.55:8200
$ sudo systemctl restart vault
$ docker exec -it vault vault unseal -ca-cert=/tmp/tmp_ca/ca.cer -address=https://127.0.0.1:8200
Key (will be hidden):
Sealed: true
Key Shares: 5
Key Threshold: 3
Unseal Progress: 1
$ docker exec -it vault vault unseal -ca-cert=/tmp/tmp_ca/ca.cer -address=https://127.0.0.1:8200
Key (will be hidden):
Sealed: true
Key Shares: 5
Key Threshold: 3
Unseal Progress: 2
$ docker exec -it vault vault unseal -ca-cert=/tmp/tmp_ca/ca.cer -address=https://127.0.0.1:8200
Key (will be hidden):
Error: Error making API request.
URL: PUT https://127.0.0.1:8200/v1/sys/unseal
Code: 500. Errors:
core@ip-10-0-10-31 ~ $ docker exec -it vault vault status -address=https://127.0.0.1:8200
Error checking seal status: Error making API request.
URL: GET https://127.0.0.1:8200/v1/sys/seal-status
Code: 500. Errors:
Aug 10 16:22:40 ip-10-0-10-31.us-west-2.compute.internal systemd[1]: Stopping vault service...
Aug 10 16:22:40 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: Using default tag: latest
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: latest: Pulling from skippy/vault.dev
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: fae91920dcd4: Already exists
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: a3ed95caeb02: Already exists
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: a3ed95caeb02: Already exists
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: a3ed95caeb02: Already exists
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: aafd30bd65c5: Already exists
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: d0cbf1bc2f86: Already exists
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: a3ed95caeb02: Already exists
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: a3ed95caeb02: Already exists
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: a3ed95caeb02: Already exists
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 7529f9a8184c: Pulling fs layer
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: a3ed95caeb02: Pulling fs layer
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 96ea0ccdd577: Pulling fs layer
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: a42ce11e17ad: Pulling fs layer
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 56d343f2a022: Pulling fs layer
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 26d9fca872ba: Pulling fs layer
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 2ffbb6559076: Pulling fs layer
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 6847a334d24b: Pulling fs layer
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: ddf95999431e: Pulling fs layer
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: a42ce11e17ad: Waiting
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 56d343f2a022: Waiting
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 26d9fca872ba: Waiting
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 2ffbb6559076: Waiting
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 6847a334d24b: Waiting
Aug 10 16:22:42 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: ddf95999431e: Waiting
Aug 10 16:22:43 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: a3ed95caeb02: Verifying Checksum
Aug 10 16:22:43 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: a3ed95caeb02: Download complete
Aug 10 16:22:43 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 7529f9a8184c: Verifying Checksum
Aug 10 16:22:43 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 7529f9a8184c: Download complete
Aug 10 16:22:43 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 7529f9a8184c: Pull complete
Aug 10 16:22:43 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 7529f9a8184c: Pull complete
Aug 10 16:22:43 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: a42ce11e17ad: Verifying Checksum
Aug 10 16:22:43 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: a42ce11e17ad: Download complete
Aug 10 16:22:43 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: a3ed95caeb02: Pull complete
Aug 10 16:22:43 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: a3ed95caeb02: Pull complete
Aug 10 16:22:44 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 56d343f2a022: Verifying Checksum
Aug 10 16:22:44 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 56d343f2a022: Download complete
Aug 10 16:22:44 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 26d9fca872ba: Verifying Checksum
Aug 10 16:22:44 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 26d9fca872ba: Download complete
Aug 10 16:22:45 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 96ea0ccdd577: Verifying Checksum
Aug 10 16:22:45 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 96ea0ccdd577: Download complete
Aug 10 16:22:45 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 2ffbb6559076: Verifying Checksum
Aug 10 16:22:45 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 2ffbb6559076: Download complete
Aug 10 16:22:46 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 6847a334d24b: Verifying Checksum
Aug 10 16:22:46 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 6847a334d24b: Download complete
Aug 10 16:22:46 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: ddf95999431e: Verifying Checksum
Aug 10 16:22:46 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: ddf95999431e: Download complete
Aug 10 16:22:51 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 96ea0ccdd577: Pull complete
Aug 10 16:22:51 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 96ea0ccdd577: Pull complete
Aug 10 16:22:52 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: a42ce11e17ad: Pull complete
Aug 10 16:22:52 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: a42ce11e17ad: Pull complete
Aug 10 16:22:53 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 56d343f2a022: Pull complete
Aug 10 16:22:53 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 56d343f2a022: Pull complete
Aug 10 16:22:54 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 26d9fca872ba: Pull complete
Aug 10 16:22:54 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 26d9fca872ba: Pull complete
Aug 10 16:22:54 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 2ffbb6559076: Pull complete
Aug 10 16:22:54 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 2ffbb6559076: Pull complete
Aug 10 16:22:55 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 6847a334d24b: Pull complete
Aug 10 16:22:55 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: 6847a334d24b: Pull complete
Aug 10 16:22:55 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: ddf95999431e: Pull complete
Aug 10 16:22:55 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: ddf95999431e: Pull complete
Aug 10 16:22:56 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: Digest: sha256:5b674d845f7bc041ccc171f07de30f67b5218f3974c13e8bd822ff2339d29d96
Aug 10 16:22:56 ip-10-0-10-31.us-west-2.compute.internal flock[18564]: Status: Downloaded newer image for skippy/vault.dev:latest
Aug 10 16:22:56 ip-10-0-10-31.us-west-2.compute.internal docker[12644]: 2016/08/10 16:22:56 [INFO]: physical/consul: Shutting down consul backend
Aug 10 16:22:56 ip-10-0-10-31.us-west-2.compute.internal docker[12644]: ==> Vault shutdown triggered
Aug 10 16:23:05 ip-10-0-10-31.us-west-2.compute.internal docker[12644]: 2016/08/10 16:23:05 [INFO] core: vault is sealed
Aug 10 16:23:05 ip-10-0-10-31.us-west-2.compute.internal docker[12644]: 2016/08/10 16:23:05 [WARN]: physical/consul: Concurrent sealed state change notify dropped
Aug 10 16:23:06 ip-10-0-10-31.us-west-2.compute.internal bash[19168]: vault
Aug 10 16:23:06 ip-10-0-10-31.us-west-2.compute.internal bash[19436]: Failed to remove container (vault): Error response from daemon: No such container: vault
Aug 10 16:23:06 ip-10-0-10-31.us-west-2.compute.internal systemd[1]: Stopped vault service.
Aug 10 16:23:06 ip-10-0-10-31.us-west-2.compute.internal systemd[1]: Starting vault service...
Aug 10 16:23:07 ip-10-0-10-31.us-west-2.compute.internal docker[19444]: Failed to kill container (vault): Error response from daemon: Cannot kill container vault: No such container: vault
Aug 10 16:23:07 ip-10-0-10-31.us-west-2.compute.internal docker[19472]: Failed to remove container (vault): Error response from daemon: No such container: vault
Aug 10 16:23:07 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: Using default tag: latest
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: latest: Pulling from skippy/vault.dev
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: fae91920dcd4: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: a3ed95caeb02: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: a3ed95caeb02: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: a3ed95caeb02: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: aafd30bd65c5: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: d0cbf1bc2f86: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: a3ed95caeb02: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: a3ed95caeb02: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: a3ed95caeb02: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: 7529f9a8184c: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: a3ed95caeb02: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: a3ed95caeb02: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: a3ed95caeb02: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: a3ed95caeb02: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: a3ed95caeb02: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: a3ed95caeb02: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: a3ed95caeb02: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: 96ea0ccdd577: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: a42ce11e17ad: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: a3ed95caeb02: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: 56d343f2a022: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: 26d9fca872ba: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: 2ffbb6559076: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: 6847a334d24b: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: ddf95999431e: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: a3ed95caeb02: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: a3ed95caeb02: Already exists
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: Digest: sha256:5b674d845f7bc041ccc171f07de30f67b5218f3974c13e8bd822ff2339d29d96
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal flock[19482]: Status: Image is up to date for skippy/vault.dev:latest
Aug 10 16:23:10 ip-10-0-10-31.us-west-2.compute.internal systemd[1]: Started vault service.
Aug 10 16:23:11 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: [manage_vault_tls.sh] START: tmp tls for vault API
Aug 10 16:23:12 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: Generating a 2048 bit RSA private key
Aug 10 16:23:12 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: .......................................+++
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: .........................................................................................................................+++
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: writing new private key to '/tmp/tmp_ca/ca_key.pem'
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: -----
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: Generating a 2048 bit RSA private key
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: .........................+++
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: ................................................................................................+++
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: writing new private key to '/tmp/active.vault.service.consul.key'
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: -----
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: Using configuration from tmp_vault_ca.cnf
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: Check that the request matches the signature
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: Signature ok
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: The Subject's Distinguished Name is as follows
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: countryName :PRINTABLE:'AU'
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: stateOrProvinceName :ASN.1 12:'Some-State'
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: organizationName :ASN.1 12:'Internet Widgits Pty Ltd'
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: Certificate is to be certified until Aug 11 16:23:13 2016 GMT (1 days)
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: Write out database with 1 new entries
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: Data Base Updated
Aug 10 16:23:13 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: [manage_vault_tls.sh] FINISH: tmp tls for vault API
Aug 10 16:23:14 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: 2016/08/10 16:23:13 [DEBUG]: physical/consul: config path set to vault/
Aug 10 16:23:14 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: 2016/08/10 16:23:13 [DEBUG]: physical/consul: config disable_registration set to false
Aug 10 16:23:14 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: 2016/08/10 16:23:13 [DEBUG]: physical/consul: config service set to vault
Aug 10 16:23:14 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: 2016/08/10 16:23:13 [DEBUG]: physical/consul: config service-tags set to
Aug 10 16:23:14 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: 2016/08/10 16:23:13 [DEBUG]: physical/consul: config address set to 0.0.0.0:8500
Aug 10 16:23:14 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: 2016/08/10 16:23:13 [DEBUG]: physical/consul: config scheme set to http
Aug 10 16:23:14 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: ==> Vault server configuration:
Aug 10 16:23:14 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: Advertise Address: https://10.0.10.31:8200
Aug 10 16:23:14 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: Backend: consul (HA available)
Aug 10 16:23:14 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: Listener 1: tcp (addr: "0.0.0.0:8200", tls: "enabled")
Aug 10 16:23:14 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: Log Level: debug
Aug 10 16:23:14 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: Mlock: supported: true, enabled: true
Aug 10 16:23:14 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: Version: Vault v0.6.1-rc1 ('b251cf7953eb77551a38ffc7c910f37a639c0f2d+CHANGES')
Aug 10 16:23:14 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: ==> Vault server started! Log data will stream in below:
Aug 10 16:23:18 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: [manage_vault_tls.sh] waiting for vault to be unsealed on host
Aug 10 16:23:21 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: 2016/08/10 16:23:21 [DEBUG] core: cannot unseal, have 1 of 3 keys
Aug 10 16:23:23 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: [manage_vault_tls.sh] waiting for vault to be unsealed on host
Aug 10 16:23:25 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: 2016/08/10 16:23:25 [DEBUG] core: cannot unseal, have 2 of 3 keys
Aug 10 16:23:28 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: 2016/08/10 16:23:28 [INFO] core: vault is unsealed
Aug 10 16:23:28 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: 2016/08/10 16:23:28 [WARN]: physical/consul: Concurrent sealed state change notify dropped
Aug 10 16:23:28 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: 2016/08/10 16:23:28 [INFO] core: entering standby mode
Aug 10 16:23:29 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: [manage_vault_tls.sh] vault unsealed; reloading TLS
Aug 10 16:23:29 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: [manage_vault_tls.sh] rotating vault tls with vault pki certs
Aug 10 16:23:30 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: [manage_vault_tls.sh] logged in via aws-ec2 and app_role to setup vault TLS
Aug 10 16:23:30 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: [manage_vault_tls.sh] retrieving certs from vault 'pki/internal-services/issue/vault'
Aug 10 16:23:30 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: [manage_vault_tls.sh] reloading vault TLS (pid 35)
Aug 10 16:23:30 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: ==> Vault reload triggered
Aug 10 16:23:35 ip-10-0-10-31.us-west-2.compute.internal docker[19555]: [manage_vault_tls.sh] reloading tls cert in 1355857 secs or ~ 376 hours (cert ttl: 2592000 secs or ~ 720 hours)
$ journalctl -u vault -f
-- Logs begin at Tue 2016-07-19 21:01:35 UTC. --
Aug 10 16:11:28 ip-10-0-10-31.us-west-2.compute.internal systemd[1]: Stopping vault service...
Aug 10 16:11:28 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: Using default tag: latest
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: latest: Pulling from skippy/vault.dev
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: fae91920dcd4: Already exists
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: a3ed95caeb02: Already exists
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: a3ed95caeb02: Already exists
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: a3ed95caeb02: Already exists
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: b7793db3d025: Pulling fs layer
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 75b418a6d999: Pulling fs layer
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: a3ed95caeb02: Pulling fs layer
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: c64c7d788637: Pulling fs layer
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: fe4501f453a4: Pulling fs layer
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 0840d4c50374: Pulling fs layer
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 44c2180320f3: Pulling fs layer
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 9c1c5299c870: Pulling fs layer
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: e89bede8a94b: Pulling fs layer
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 67454f978aad: Pulling fs layer
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: c90f88520546: Pulling fs layer
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: c64c7d788637: Waiting
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: fe4501f453a4: Waiting
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 0840d4c50374: Waiting
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 44c2180320f3: Waiting
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 9c1c5299c870: Waiting
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: e89bede8a94b: Waiting
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 67454f978aad: Waiting
Aug 10 16:11:29 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: c90f88520546: Waiting
Aug 10 16:11:30 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: a3ed95caeb02: Verifying Checksum
Aug 10 16:11:30 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: a3ed95caeb02: Download complete
Aug 10 16:11:30 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: c64c7d788637: Verifying Checksum
Aug 10 16:11:30 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: c64c7d788637: Download complete
Aug 10 16:11:31 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 75b418a6d999: Verifying Checksum
Aug 10 16:11:31 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 75b418a6d999: Download complete
Aug 10 16:11:32 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 0840d4c50374: Verifying Checksum
Aug 10 16:11:32 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 0840d4c50374: Download complete
Aug 10 16:11:32 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 44c2180320f3: Verifying Checksum
Aug 10 16:11:32 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 44c2180320f3: Download complete
Aug 10 16:11:33 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: b7793db3d025: Verifying Checksum
Aug 10 16:11:33 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: b7793db3d025: Download complete
Aug 10 16:11:34 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: fe4501f453a4: Verifying Checksum
Aug 10 16:11:34 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: fe4501f453a4: Download complete
Aug 10 16:11:35 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 9c1c5299c870: Verifying Checksum
Aug 10 16:11:35 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 9c1c5299c870: Download complete
Aug 10 16:11:36 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: e89bede8a94b: Verifying Checksum
Aug 10 16:11:36 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: e89bede8a94b: Download complete
Aug 10 16:11:37 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 67454f978aad: Verifying Checksum
Aug 10 16:11:37 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 67454f978aad: Download complete
Aug 10 16:11:39 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: c90f88520546: Verifying Checksum
Aug 10 16:11:39 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: c90f88520546: Download complete
Aug 10 16:11:47 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: b7793db3d025: Pull complete
Aug 10 16:11:47 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: b7793db3d025: Pull complete
Aug 10 16:11:47 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 75b418a6d999: Pull complete
Aug 10 16:11:47 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 75b418a6d999: Pull complete
Aug 10 16:11:48 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: a3ed95caeb02: Pull complete
Aug 10 16:11:48 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: a3ed95caeb02: Pull complete
Aug 10 16:11:49 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: c64c7d788637: Pull complete
Aug 10 16:11:49 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: c64c7d788637: Pull complete
Aug 10 16:12:05 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: fe4501f453a4: Pull complete
Aug 10 16:12:05 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: fe4501f453a4: Pull complete
Aug 10 16:12:10 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 0840d4c50374: Pull complete
Aug 10 16:12:10 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 0840d4c50374: Pull complete
Aug 10 16:12:18 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 44c2180320f3: Pull complete
Aug 10 16:12:18 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 44c2180320f3: Pull complete
Aug 10 16:12:19 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 9c1c5299c870: Pull complete
Aug 10 16:12:19 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 9c1c5299c870: Pull complete
Aug 10 16:12:20 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: e89bede8a94b: Pull complete
Aug 10 16:12:20 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: e89bede8a94b: Pull complete
Aug 10 16:12:20 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 67454f978aad: Pull complete
Aug 10 16:12:20 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: 67454f978aad: Pull complete
Aug 10 16:12:21 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: c90f88520546: Pull complete
Aug 10 16:12:21 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: c90f88520546: Pull complete
Aug 10 16:12:22 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: Digest: sha256:bd138e5180836220dd9267c2af401fd5aa060cffcb739adf29b185016290a056
Aug 10 16:12:22 ip-10-0-10-31.us-west-2.compute.internal flock[31334]: Status: Downloaded newer image for skippy/vault.dev:latest
Aug 10 16:12:22 ip-10-0-10-31.us-west-2.compute.internal docker[19298]: ==> Vault shutdown triggered
Aug 10 16:12:25 ip-10-0-10-31.us-west-2.compute.internal docker[19298]: 2016/08/10 16:12:25 [INFO] core: vault is sealed
Aug 10 16:12:25 ip-10-0-10-31.us-west-2.compute.internal docker[19298]: 2016/08/10 16:12:25 [WARN]: physical/consul: Concurrent sealed state change notify dropped
Aug 10 16:12:25 ip-10-0-10-31.us-west-2.compute.internal bash[722]: vault
Aug 10 16:12:25 ip-10-0-10-31.us-west-2.compute.internal bash[767]: Failed to remove container (vault): Error response from daemon: No such container: vault
Aug 10 16:12:25 ip-10-0-10-31.us-west-2.compute.internal systemd[1]: Stopped vault service.
Aug 10 16:12:25 ip-10-0-10-31.us-west-2.compute.internal systemd[1]: Starting vault service...
Aug 10 16:12:25 ip-10-0-10-31.us-west-2.compute.internal docker[776]: Failed to kill container (vault): Error response from daemon: Cannot kill container vault: No such container: vault
Aug 10 16:12:26 ip-10-0-10-31.us-west-2.compute.internal docker[792]: Failed to remove container (vault): Error response from daemon: No such container: vault
Aug 10 16:12:26 ip-10-0-10-31.us-west-2.compute.internal flock[801]: Using default tag: latest
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: latest: Pulling from skippy/vault.dev
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: fae91920dcd4: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: a3ed95caeb02: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: a3ed95caeb02: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: a3ed95caeb02: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: b7793db3d025: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: 75b418a6d999: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: a3ed95caeb02: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: a3ed95caeb02: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: a3ed95caeb02: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: c64c7d788637: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: a3ed95caeb02: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: a3ed95caeb02: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: a3ed95caeb02: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: a3ed95caeb02: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: a3ed95caeb02: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: a3ed95caeb02: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: a3ed95caeb02: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: fe4501f453a4: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: 0840d4c50374: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: a3ed95caeb02: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: 44c2180320f3: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: 9c1c5299c870: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: e89bede8a94b: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: 67454f978aad: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: c90f88520546: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: a3ed95caeb02: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: a3ed95caeb02: Already exists
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: Digest: sha256:bd138e5180836220dd9267c2af401fd5aa060cffcb739adf29b185016290a056
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal flock[801]: Status: Image is up to date for skippy/vault.dev:latest
Aug 10 16:12:27 ip-10-0-10-31.us-west-2.compute.internal systemd[1]: Started vault service.
Aug 10 16:12:28 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] START: tmp tls for vault API
Aug 10 16:12:28 ip-10-0-10-31.us-west-2.compute.internal docker[823]: Generating a 2048 bit RSA private key
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: ............................................+++
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: .............................................+++
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: writing new private key to '/tmp/tmp_ca/ca_key.pem'
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: -----
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: Generating a 2048 bit RSA private key
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: .......................+++
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: ...........................+++
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: writing new private key to '/tmp/active.vault.service.consul.key'
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: -----
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: Using configuration from tmp_vault_ca.cnf
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: Check that the request matches the signature
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: Signature ok
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: The Subject's Distinguished Name is as follows
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: countryName :PRINTABLE:'AU'
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: stateOrProvinceName :ASN.1 12:'Some-State'
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: organizationName :ASN.1 12:'Internet Widgits Pty Ltd'
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: Certificate is to be certified until Aug 11 16:12:29 2016 GMT (1 days)
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: Write out database with 1 new entries
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: Data Base Updated
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] FINISH: tmp tls for vault API
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: 2016/08/10 16:12:29 [DEBUG]: physical/consul: config path set to vault/
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: 2016/08/10 16:12:29 [DEBUG]: physical/consul: config disable_registration set to false
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: 2016/08/10 16:12:29 [DEBUG]: physical/consul: config service set to vault
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: 2016/08/10 16:12:29 [DEBUG]: physical/consul: config service-tags set to
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: 2016/08/10 16:12:29 [DEBUG]: physical/consul: config address set to 0.0.0.0:8500
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: 2016/08/10 16:12:29 [DEBUG]: physical/consul: config scheme set to http
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: ==> Vault server configuration:
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: Advertise Address: https://10.0.10.31:8200
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: Backend: consul (HA available)
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: Listener 1: tcp (addr: "0.0.0.0:8200", tls: "enabled")
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: Log Level: debug
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: Mlock: supported: true, enabled: true
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: Version: Vault v0.6.1-rc2 ('25e45c004d95c6539d952e86c96287d585c09c46+CHANGES')
Aug 10 16:12:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: ==> Vault server started! Log data will stream in below:
Aug 10 16:12:34 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] waiting for vault to be unsealed on host
Aug 10 16:12:39 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] waiting for vault to be unsealed on host
Aug 10 16:12:44 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] waiting for vault to be unsealed on host
Aug 10 16:12:49 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] waiting for vault to be unsealed on host
Aug 10 16:12:54 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] waiting for vault to be unsealed on host
Aug 10 16:12:59 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] waiting for vault to be unsealed on host
Aug 10 16:13:08 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] waiting for vault to be unsealed on host
Aug 10 16:13:10 ip-10-0-10-31.us-west-2.compute.internal docker[823]: 2016/08/10 16:13:10 [DEBUG] core: cannot unseal, have 1 of 3 keys
Aug 10 16:13:13 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] waiting for vault to be unsealed on host
Aug 10 16:13:15 ip-10-0-10-31.us-west-2.compute.internal docker[823]: 2016/08/10 16:13:15 [DEBUG] core: cannot unseal, have 2 of 3 keys
Aug 10 16:13:18 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] waiting for vault to be unsealed on host
Aug 10 16:13:19 ip-10-0-10-31.us-west-2.compute.internal docker[823]: 2016/08/10 16:13:19 [INFO] core: vault is unsealed
Aug 10 16:13:19 ip-10-0-10-31.us-west-2.compute.internal docker[823]: 2016/08/10 16:13:19 [WARN]: physical/consul: Concurrent sealed state change notify dropped
Aug 10 16:13:19 ip-10-0-10-31.us-west-2.compute.internal docker[823]: 2016/08/10 16:13:19 [INFO] core: entering standby mode
Aug 10 16:13:23 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] vault unsealed; reloading TLS
Aug 10 16:13:23 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] rotating vault tls with vault pki certs
Aug 10 16:13:24 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] failed retrieving auth_app_role-based token
Aug 10 16:13:24 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] failed to setup vault tls; try again in 5 seconds
Aug 10 16:13:29 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] rotating vault tls with vault pki certs
Aug 10 16:13:30 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] logged in via aws-ec2 and app_role to setup vault TLS
Aug 10 16:13:30 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] retrieving certs from vault 'pki/internal-services/issue/vault'
Aug 10 16:13:31 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] reloading vault TLS (pid 36)
Aug 10 16:13:31 ip-10-0-10-31.us-west-2.compute.internal docker[823]: ==> Vault reload triggered
Aug 10 16:13:36 ip-10-0-10-31.us-west-2.compute.internal docker[823]: [manage_vault_tls.sh] reloading tls cert in 1908369 secs or ~ 530 hours (cert ttl: 2592000 secs or ~ 720 hours)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment