mirror of
https://github.com/galaxyproject/galaxy.git
synced 2026-09-24 16:30:27 +08:00
co-authored by
Enis Afgan
parent
be9f210901
commit
d4fe61a424
@@ -1,7 +1,7 @@
|
||||
# Storing secrets in the vault
|
||||
|
||||
Galaxy can be configured to store secrets in an external vault, which is useful for secure handling and centralization of secrets management.
|
||||
In particular, information fields in the "Manage information" section of the user profile, such as a dropbox password, can be configured to be stored
|
||||
In particular, information fields in the "Manage information" section of the user profile, such as AWS credentials, can be configured to be stored
|
||||
in an encrypted vault instead of the database. Vault keys are generally stored as key-value pairs in a hierarchical fashion, for example:
|
||||
`/galaxy/user/2/preferences/aws/client_secret`.
|
||||
|
||||
@@ -13,7 +13,7 @@ There are currently 3 supported backends.
|
||||
|-------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
|
||||
| hashicorp | Hashicorp Vault is a secrets and encryption management system. https://www.vaultproject.io/ |
|
||||
| custos | Custos is an NSF-funded project, backed by open source software that provides science gateways such as Galaxy with single sign-on, group management, and management of secrets such as access keys and OAuth2 access tokens. Custos secrets management is backed by Hashicorp's vault, but provides a convenient, always-on ReST API service. |
|
||||
| database | The database backend stores secrets in an encrypted table in the Galaxy database itself. It is a convenient way to get started with a vault, and while it supports basic key rotation, we recommend using one of the above 2 options in production. |
|
||||
| database | The database backend stores secrets in an encrypted table in the Galaxy database itself. It is a convenient way to get started with a vault, and while it supports basic key rotation, we recommend using one of the other options in production. |
|
||||
|
||||
## Configuring Galaxy
|
||||
|
||||
@@ -36,7 +36,9 @@ path_prefix: /galaxy # optional
|
||||
...
|
||||
```
|
||||
|
||||
The `type` must be a valid backend type. The `path_prefix` property indicates the root path under which to store all vault keys. If multiple Galaxy instances are using the same Vault, a prefix can be used to identify the galaxy instance uniquely for example.
|
||||
The `type` must be a valid backend type: `hashicorp`, `custos`, or `database`. At present, only a single vault backend
|
||||
is supported. The `path_prefix` property indicates the root path under which to store all vault keys. If multiple
|
||||
Galaxy instances are using the same vault, a prefix can be used to uniquely identify the Galaxy instance.
|
||||
If no path_prefix is provided, the prefix defaults to `/galaxy`.
|
||||
|
||||
## Vault configuration for Hashicorp Vault
|
||||
@@ -45,7 +47,7 @@ If no path_prefix is provided, the prefix defaults to `/galaxy`.
|
||||
type: hashicorp
|
||||
path_prefix: /my_galaxy_instance
|
||||
vault_address: http://localhost:8200
|
||||
vault_token: galaxy_test_token
|
||||
vault_token: vault_application_token
|
||||
```
|
||||
|
||||
## Vault configuration for Custos
|
||||
@@ -58,6 +60,9 @@ custos_client_id: custos-jeREDACTEDye-10000001
|
||||
custos_client_sec: OGREDACTEDBSUDHn
|
||||
```
|
||||
|
||||
Obtaining the Custos client id and client secret requires first registering your Galaxy instance with Custos.
|
||||
Visit [usecustos.org](http://usecustos.org/) for more information.
|
||||
|
||||
## Vault configuration for database
|
||||
|
||||
```yaml
|
||||
@@ -82,7 +87,8 @@ from cryptography.fernet import Fernet
|
||||
Fernet.generate_key().decode('utf-8')
|
||||
|
||||
If multiple encryption keys are defined, only the first key is used to encrypt secrets. The remaining keys are tried in turn during decryption. This is useful for key rotation.
|
||||
We recommend periodically generating a new fernet key and rotating old keys.
|
||||
We recommend periodically generating a new fernet key and rotating old keys. However, before removing an old key, make sure that any data encrypted using that old key is no longer
|
||||
present or the data will no longer be decryptable.
|
||||
|
||||
## Configuring user preferences to use the vault
|
||||
|
||||
|
||||
@@ -1,5 +1,9 @@
|
||||
# to run tests, start vault with:
|
||||
# $ vault server -dev -dev-root-token-id=galaxy_test_token
|
||||
# $ vault server -dev -dev-root-token-id=vault_application_token
|
||||
# The Vault application token can is obtained using command `vault token create`.
|
||||
# If running the vault server in -dev mode, a token is displayed at startup as a root token.
|
||||
# For more info on how to obtain Vault tokens, see the
|
||||
# [Vault documentation](https://learn.hashicorp.com/tutorials/vault/getting-started-authentication?in=vault/getting-started#token-authentication).
|
||||
type: hashicorp
|
||||
path_prefix: /my_galaxy_instance
|
||||
vault_address: ${vault_address}
|
||||
|
||||
Reference in New Issue
Block a user