From 87bb031ed00b7993a29d74aee2e89875c5444caf Mon Sep 17 00:00:00 2001 From: Alex Auvolat Date: Sun, 25 Dec 2022 22:31:18 +0100 Subject: Migrate prod cluster secrets to new format --- cluster/prod/app/backup/secrets.toml | 90 ++++++++++++++++++++++ .../secrets/backup/consul/backup_aws_access_key_id | 1 - .../backup/consul/backup_aws_secret_access_key | 1 - .../secrets/backup/consul/backup_restic_password | 1 - .../secrets/backup/consul/backup_restic_repository | 1 - .../backup/cryptpad/backup_aws_access_key_id | 1 - .../backup/cryptpad/backup_aws_secret_access_key | 1 - .../secrets/backup/cryptpad/backup_restic_password | 1 - .../backup/cryptpad/backup_restic_repository | 1 - cluster/prod/app/backup/secrets/backup/id_ed25519 | 1 - .../prod/app/backup/secrets/backup/id_ed25519.pub | 1 - .../backup/secrets/backup/psql/aws_access_key_id | 1 - .../secrets/backup/psql/aws_secret_access_key | 1 - .../backup/secrets/backup/psql/crypt_private_key | 1 - .../backup/secrets/backup/psql/crypt_public_key | 1 - .../prod/app/backup/secrets/backup/target_ssh_dir | 1 - .../backup/secrets/backup/target_ssh_fingerprint | 1 - .../prod/app/backup/secrets/backup/target_ssh_host | 1 - .../prod/app/backup/secrets/backup/target_ssh_port | 1 - .../prod/app/backup/secrets/backup/target_ssh_user | 1 - 20 files changed, 90 insertions(+), 19 deletions(-) create mode 100644 cluster/prod/app/backup/secrets.toml delete mode 100644 cluster/prod/app/backup/secrets/backup/consul/backup_aws_access_key_id delete mode 100644 cluster/prod/app/backup/secrets/backup/consul/backup_aws_secret_access_key delete mode 100644 cluster/prod/app/backup/secrets/backup/consul/backup_restic_password delete mode 100644 cluster/prod/app/backup/secrets/backup/consul/backup_restic_repository delete mode 100644 cluster/prod/app/backup/secrets/backup/cryptpad/backup_aws_access_key_id delete mode 100644 cluster/prod/app/backup/secrets/backup/cryptpad/backup_aws_secret_access_key delete mode 100644 cluster/prod/app/backup/secrets/backup/cryptpad/backup_restic_password delete mode 100644 cluster/prod/app/backup/secrets/backup/cryptpad/backup_restic_repository delete mode 100644 cluster/prod/app/backup/secrets/backup/id_ed25519 delete mode 100644 cluster/prod/app/backup/secrets/backup/id_ed25519.pub delete mode 100644 cluster/prod/app/backup/secrets/backup/psql/aws_access_key_id delete mode 100644 cluster/prod/app/backup/secrets/backup/psql/aws_secret_access_key delete mode 100644 cluster/prod/app/backup/secrets/backup/psql/crypt_private_key delete mode 100644 cluster/prod/app/backup/secrets/backup/psql/crypt_public_key delete mode 100644 cluster/prod/app/backup/secrets/backup/target_ssh_dir delete mode 100644 cluster/prod/app/backup/secrets/backup/target_ssh_fingerprint delete mode 100644 cluster/prod/app/backup/secrets/backup/target_ssh_host delete mode 100644 cluster/prod/app/backup/secrets/backup/target_ssh_port delete mode 100644 cluster/prod/app/backup/secrets/backup/target_ssh_user (limited to 'cluster/prod/app/backup') diff --git a/cluster/prod/app/backup/secrets.toml b/cluster/prod/app/backup/secrets.toml new file mode 100644 index 0000000..5d2b851 --- /dev/null +++ b/cluster/prod/app/backup/secrets.toml @@ -0,0 +1,90 @@ +# Cryptpad backup + +[secrets."backup/cryptpad/backup_restic_password"] +type = 'user' +description = 'Restic password to encrypt backups' + +[secrets."backup/cryptpad/backup_aws_secret_access_key"] +type = 'user' +description = 'Backup AWS secret access key' + +[secrets."backup/cryptpad/backup_restic_repository"] +type = 'user' +description = 'Restic repository' +example = 's3:https://s3.garage.tld' + +[secrets."backup/cryptpad/backup_aws_access_key_id"] +type = 'user' +description = 'Backup AWS access key ID' + + +# Consul backup + +[secrets."backup/consul/backup_restic_password"] +type = 'user' +description = 'Restic password to encrypt backups' + +[secrets."backup/consul/backup_aws_secret_access_key"] +type = 'user' +description = 'Backup AWS secret access key' + +[secrets."backup/consul/backup_restic_repository"] +type = 'user' +description = 'Restic repository' +example = 's3:https://s3.garage.tld' + +[secrets."backup/consul/backup_aws_access_key_id"] +type = 'user' +description = 'Backup AWS access key ID' + + +# Postgresql backup + +[secrets."backup/psql/aws_secret_access_key"] +type = 'user' +description = 'Minio secret key' + +[secrets."backup/psql/aws_access_key_id"] +type = 'user' +description = 'Minio access key' + +[secrets."backup/psql/crypt_public_key"] +type = 'user' +description = 'A public key to encypt backups with age' + +[secrets."backup/psql/crypt_private_key"] +type = 'user' +description = 'a private key to decript backups from age' + + +# SSH target config (do we still use this?) + +[secrets."backup/target_ssh_host"] +type = 'user' +description = 'Hostname of the backup target host' + +[secrets."backup/target_ssh_port"] +type = 'user' +description = 'SSH port number to connect to the target host' + +[secrets."backup/target_ssh_dir"] +type = 'user' +description = 'Directory where to store backups on target host' + +[secrets."backup/target_ssh_user"] +type = 'user' +description = 'SSH username to log in as on the target host' + +[secrets."backup/target_ssh_fingerprint"] +type = 'user' +description = 'SSH fingerprint of the target machine (format: copy here the corresponding line from your known_hosts file)' + +[secrets."backup/id_ed25519"] +type = 'user' +multiline = true +description = 'Private ed25519 key of the container doing the backup' + +[secrets."backup/id_ed25519.pub"] +type = 'user' +description = 'Public ed25519 key of the container doing the backup (this key must be in authorized_keys on the backup target host)' + diff --git a/cluster/prod/app/backup/secrets/backup/consul/backup_aws_access_key_id b/cluster/prod/app/backup/secrets/backup/consul/backup_aws_access_key_id deleted file mode 100644 index 9235e53..0000000 --- a/cluster/prod/app/backup/secrets/backup/consul/backup_aws_access_key_id +++ /dev/null @@ -1 +0,0 @@ -USER Backup AWS access key ID diff --git a/cluster/prod/app/backup/secrets/backup/consul/backup_aws_secret_access_key b/cluster/prod/app/backup/secrets/backup/consul/backup_aws_secret_access_key deleted file mode 100644 index f34677e..0000000 --- a/cluster/prod/app/backup/secrets/backup/consul/backup_aws_secret_access_key +++ /dev/null @@ -1 +0,0 @@ -USER Backup AWS secret access key diff --git a/cluster/prod/app/backup/secrets/backup/consul/backup_restic_password b/cluster/prod/app/backup/secrets/backup/consul/backup_restic_password deleted file mode 100644 index fbaa5fa..0000000 --- a/cluster/prod/app/backup/secrets/backup/consul/backup_restic_password +++ /dev/null @@ -1 +0,0 @@ -USER Restic password to encrypt backups diff --git a/cluster/prod/app/backup/secrets/backup/consul/backup_restic_repository b/cluster/prod/app/backup/secrets/backup/consul/backup_restic_repository deleted file mode 100644 index 3f6cb93..0000000 --- a/cluster/prod/app/backup/secrets/backup/consul/backup_restic_repository +++ /dev/null @@ -1 +0,0 @@ -USER Restic repository, eg. s3:https://s3.garage.tld diff --git a/cluster/prod/app/backup/secrets/backup/cryptpad/backup_aws_access_key_id b/cluster/prod/app/backup/secrets/backup/cryptpad/backup_aws_access_key_id deleted file mode 100644 index 9235e53..0000000 --- a/cluster/prod/app/backup/secrets/backup/cryptpad/backup_aws_access_key_id +++ /dev/null @@ -1 +0,0 @@ -USER Backup AWS access key ID diff --git a/cluster/prod/app/backup/secrets/backup/cryptpad/backup_aws_secret_access_key b/cluster/prod/app/backup/secrets/backup/cryptpad/backup_aws_secret_access_key deleted file mode 100644 index f34677e..0000000 --- a/cluster/prod/app/backup/secrets/backup/cryptpad/backup_aws_secret_access_key +++ /dev/null @@ -1 +0,0 @@ -USER Backup AWS secret access key diff --git a/cluster/prod/app/backup/secrets/backup/cryptpad/backup_restic_password b/cluster/prod/app/backup/secrets/backup/cryptpad/backup_restic_password deleted file mode 100644 index fbaa5fa..0000000 --- a/cluster/prod/app/backup/secrets/backup/cryptpad/backup_restic_password +++ /dev/null @@ -1 +0,0 @@ -USER Restic password to encrypt backups diff --git a/cluster/prod/app/backup/secrets/backup/cryptpad/backup_restic_repository b/cluster/prod/app/backup/secrets/backup/cryptpad/backup_restic_repository deleted file mode 100644 index 3f6cb93..0000000 --- a/cluster/prod/app/backup/secrets/backup/cryptpad/backup_restic_repository +++ /dev/null @@ -1 +0,0 @@ -USER Restic repository, eg. s3:https://s3.garage.tld diff --git a/cluster/prod/app/backup/secrets/backup/id_ed25519 b/cluster/prod/app/backup/secrets/backup/id_ed25519 deleted file mode 100644 index 9d7fd46..0000000 --- a/cluster/prod/app/backup/secrets/backup/id_ed25519 +++ /dev/null @@ -1 +0,0 @@ -USER_LONG Private ed25519 key of the container doing the backup diff --git a/cluster/prod/app/backup/secrets/backup/id_ed25519.pub b/cluster/prod/app/backup/secrets/backup/id_ed25519.pub deleted file mode 100644 index 0a2ab35..0000000 --- a/cluster/prod/app/backup/secrets/backup/id_ed25519.pub +++ /dev/null @@ -1 +0,0 @@ -USER Public ed25519 key of the container doing the backup (this key must be in authorized_keys on the backup target host) diff --git a/cluster/prod/app/backup/secrets/backup/psql/aws_access_key_id b/cluster/prod/app/backup/secrets/backup/psql/aws_access_key_id deleted file mode 100644 index 82375d7..0000000 --- a/cluster/prod/app/backup/secrets/backup/psql/aws_access_key_id +++ /dev/null @@ -1 +0,0 @@ -USER Minio access key diff --git a/cluster/prod/app/backup/secrets/backup/psql/aws_secret_access_key b/cluster/prod/app/backup/secrets/backup/psql/aws_secret_access_key deleted file mode 100644 index de5090c..0000000 --- a/cluster/prod/app/backup/secrets/backup/psql/aws_secret_access_key +++ /dev/null @@ -1 +0,0 @@ -USER Minio secret key diff --git a/cluster/prod/app/backup/secrets/backup/psql/crypt_private_key b/cluster/prod/app/backup/secrets/backup/psql/crypt_private_key deleted file mode 100644 index 4abece9..0000000 --- a/cluster/prod/app/backup/secrets/backup/psql/crypt_private_key +++ /dev/null @@ -1 +0,0 @@ -USER a private key to decript backups from age diff --git a/cluster/prod/app/backup/secrets/backup/psql/crypt_public_key b/cluster/prod/app/backup/secrets/backup/psql/crypt_public_key deleted file mode 100644 index 156ad47..0000000 --- a/cluster/prod/app/backup/secrets/backup/psql/crypt_public_key +++ /dev/null @@ -1 +0,0 @@ -USER A public key to encypt backups with age diff --git a/cluster/prod/app/backup/secrets/backup/target_ssh_dir b/cluster/prod/app/backup/secrets/backup/target_ssh_dir deleted file mode 100644 index 3b2a4da..0000000 --- a/cluster/prod/app/backup/secrets/backup/target_ssh_dir +++ /dev/null @@ -1 +0,0 @@ -USER Directory where to store backups on target host diff --git a/cluster/prod/app/backup/secrets/backup/target_ssh_fingerprint b/cluster/prod/app/backup/secrets/backup/target_ssh_fingerprint deleted file mode 100644 index 608f3ec..0000000 --- a/cluster/prod/app/backup/secrets/backup/target_ssh_fingerprint +++ /dev/null @@ -1 +0,0 @@ -USER SSH fingerprint of the target machine (format: copy here the corresponding line from your known_hosts file) diff --git a/cluster/prod/app/backup/secrets/backup/target_ssh_host b/cluster/prod/app/backup/secrets/backup/target_ssh_host deleted file mode 100644 index 6268f87..0000000 --- a/cluster/prod/app/backup/secrets/backup/target_ssh_host +++ /dev/null @@ -1 +0,0 @@ -USER Hostname of the backup target host diff --git a/cluster/prod/app/backup/secrets/backup/target_ssh_port b/cluster/prod/app/backup/secrets/backup/target_ssh_port deleted file mode 100644 index 309dd38..0000000 --- a/cluster/prod/app/backup/secrets/backup/target_ssh_port +++ /dev/null @@ -1 +0,0 @@ -USER SSH port number to connect to the target host diff --git a/cluster/prod/app/backup/secrets/backup/target_ssh_user b/cluster/prod/app/backup/secrets/backup/target_ssh_user deleted file mode 100644 index 98b3046..0000000 --- a/cluster/prod/app/backup/secrets/backup/target_ssh_user +++ /dev/null @@ -1 +0,0 @@ -USER SSH username to log in as on the target host -- cgit v1.2.3