This plugin has not been properly reviewed and should not be used in production.
Vault ACME is a Vault secret engine that allow users and application to retrieve TLS certificates validated by an ACME provider like Let's Encrypt without having to give each applications permission to modify DNS and using Vault's audit and policy systems.
Discussion: hashicorp/vault#4950
The documentation is available at website/source/docs/secrets/acme/index.html.md
.
Using this plugin in Docker requires to manually set the mlock
file capability
to both Vault and the acme plugin:
$ sudo setcap cap_ipc_lock=+ep $(readlink -f $(which vault))
$ sudo setcap cap_ipc_lock=+ep /vault/plugins/acme-plugin
After setting plugin_directory
and setting the correct shasum in Vault (vault write sys/plugins/catalog/secret/acme sha_256=$(sha256sum acme-plugin) command=acme-plugin
)
you can mount the plugin like any other: vault secrets enable -path acme -plugin-name acme plugin
.
Acceptance tests are run againts Pebble, a running container will be needed for them to pass:
$ docker run -d -e "PEBBLE_VA_NOSLEEP=1" -p 14000:14000 -p 15000:15000 letsencrypt/pebble pebble -dnsserver 1.1.1.1:53
$ LEGO_CA_CERTIFICATES=$PWD/test/certs/pebble.minica.pem make test