Skip to content

Commit db36693

Browse files
authored
fix: allow user defined tls variables to be set instead of hardcoded default values (#385)
* fix: pass transit tls cert and key instaid of hardcoded default * fix: update vault_transt_tls_ca_cert_file to use user provided value and keeping sensible default
1 parent daeb37a commit db36693

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

defaults/main.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -329,9 +329,9 @@ vault_transit_disable_renewal: false
329329
vault_transit_key_name: 'autounseal'
330330
vault_transit_mount_path: "transit/"
331331
# vault_transit_namespace: ''
332-
vault_transit_tls_ca_cert_file: "{{ vault_tls_ca_file }}"
333-
vault_transit_tls_client_cert_file: "autounseal_client_cert.pem"
334-
vault_transit_tls_client_key_file: "autounseal_client_key.pem"
332+
vault_transit_tls_ca_cert_file: "{{ vault_transit_tls_ca_cert_file | default(vault_tls_ca_file) }}"
333+
vault_transit_tls_client_cert_file: "{{ vault_transit_tls_client_cert | default('autounseal_client_cert.pem', true) }}"
334+
vault_transit_tls_client_key_file: "{{ vault_transit_tls_client_key | default('autounseal_client_key.pem', true) }}"
335335
# vault_transit_tls_server_name: ''
336336
vault_transit_tls_skip_verify: "{{ lookup('env', 'VAULT_SKIP_VERIFY') | default('', false) }}"
337337

0 commit comments

Comments
 (0)