Update vault docs

Co-authored-by: Enis Afgan <afgane@gmail.com>
This commit is contained in:
Nuwan Goonasekera
2021-12-20 18:40:20 +05:30
co-authored by Enis Afgan
parent be9f210901
commit d4fe61a424
2 changed files with 16 additions and 6 deletions
+11 -5
View File
@@ -1,7 +1,7 @@
# Storing secrets in the vault
Galaxy can be configured to store secrets in an external vault, which is useful for secure handling and centralization of secrets management.
In particular, information fields in the "Manage information" section of the user profile, such as a dropbox password, can be configured to be stored
In particular, information fields in the "Manage information" section of the user profile, such as AWS credentials, can be configured to be stored
in an encrypted vault instead of the database. Vault keys are generally stored as key-value pairs in a hierarchical fashion, for example:
`/galaxy/user/2/preferences/aws/client_secret`.
@@ -13,7 +13,7 @@ There are currently 3 supported backends.
|-------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| hashicorp | Hashicorp Vault is a secrets and encryption management system. https://www.vaultproject.io/ |
| custos | Custos is an NSF-funded project, backed by open source software that provides science gateways such as Galaxy with single sign-on, group management, and management of secrets such as access keys and OAuth2 access tokens. Custos secrets management is backed by Hashicorp's vault, but provides a convenient, always-on ReST API service. |
| database | The database backend stores secrets in an encrypted table in the Galaxy database itself. It is a convenient way to get started with a vault, and while it supports basic key rotation, we recommend using one of the above 2 options in production. |
| database | The database backend stores secrets in an encrypted table in the Galaxy database itself. It is a convenient way to get started with a vault, and while it supports basic key rotation, we recommend using one of the other options in production. |
## Configuring Galaxy
@@ -36,7 +36,9 @@ path_prefix: /galaxy # optional
...
```
The `type` must be a valid backend type. The `path_prefix` property indicates the root path under which to store all vault keys. If multiple Galaxy instances are using the same Vault, a prefix can be used to identify the galaxy instance uniquely for example.
The `type` must be a valid backend type: `hashicorp`, `custos`, or `database`. At present, only a single vault backend
is supported. The `path_prefix` property indicates the root path under which to store all vault keys. If multiple
Galaxy instances are using the same vault, a prefix can be used to uniquely identify the Galaxy instance.
If no path_prefix is provided, the prefix defaults to `/galaxy`.
## Vault configuration for Hashicorp Vault
@@ -45,7 +47,7 @@ If no path_prefix is provided, the prefix defaults to `/galaxy`.
type: hashicorp
path_prefix: /my_galaxy_instance
vault_address: http://localhost:8200
vault_token: galaxy_test_token
vault_token: vault_application_token
```
## Vault configuration for Custos
@@ -58,6 +60,9 @@ custos_client_id: custos-jeREDACTEDye-10000001
custos_client_sec: OGREDACTEDBSUDHn
```
Obtaining the Custos client id and client secret requires first registering your Galaxy instance with Custos.
Visit [usecustos.org](http://usecustos.org/) for more information.
## Vault configuration for database
```yaml
@@ -82,7 +87,8 @@ from cryptography.fernet import Fernet
Fernet.generate_key().decode('utf-8')
If multiple encryption keys are defined, only the first key is used to encrypt secrets. The remaining keys are tried in turn during decryption. This is useful for key rotation.
We recommend periodically generating a new fernet key and rotating old keys.
We recommend periodically generating a new fernet key and rotating old keys. However, before removing an old key, make sure that any data encrypted using that old key is no longer
present or the data will no longer be decryptable.
## Configuring user preferences to use the vault
@@ -1,5 +1,9 @@
# to run tests, start vault with:
# $ vault server -dev -dev-root-token-id=galaxy_test_token
# $ vault server -dev -dev-root-token-id=vault_application_token
# The Vault application token can is obtained using command `vault token create`.
# If running the vault server in -dev mode, a token is displayed at startup as a root token.
# For more info on how to obtain Vault tokens, see the
# [Vault documentation](https://learn.hashicorp.com/tutorials/vault/getting-started-authentication?in=vault/getting-started#token-authentication).
type: hashicorp
path_prefix: /my_galaxy_instance
vault_address: ${vault_address}