Module: Legion::Crypt::VaultCluster
Constant Summary
Logging::Helper::CompatLogger
Instance Method Summary
collapse
#handle_exception, #log
Instance Method Details
#cluster(name = nil) ⇒ Object
27
28
29
30
|
# File 'lib/legion/crypt/vault_cluster.rb', line 27
def cluster(name = nil)
name = resolve_cluster_name(name)
clusters[name]
end
|
#clusters ⇒ Object
37
38
39
|
# File 'lib/legion/crypt/vault_cluster.rb', line 37
def clusters
vault_settings[:clusters] || {}
end
|
#connect_all_clusters ⇒ Object
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
|
# File 'lib/legion/crypt/vault_cluster.rb', line 45
def connect_all_clusters
log.info "Vault cluster connect requested configured_clusters=#{clusters.size}"
log_vault_debug("connect_all_clusters: #{clusters.size} cluster(s) configured")
results = {}
clusters.each do |name, config|
log_vault_debug("connect_all_clusters: #{name} (auth_method=#{config[:auth_method].inspect})")
case config[:auth_method]&.to_s
when 'kerberos'
results[name] = connect_kerberos_cluster(name, config)
when 'ldap'
next else
next unless config[:token]
client = vault_client(name)
config[:connected] = cluster_healthy?(client)
results[name] = config[:connected]
log_cluster_connected(name, config) if config[:connected]
end
rescue StandardError => e
config[:connected] = false
results[name] = false
log_vault_error(name, e, operation: 'crypt.vault_cluster.connect_all_clusters')
end
connected = results.select { |_, v| v }
log.info "Vault cluster connect complete connected=#{connected.size} attempted=#{results.size}"
log_vault_debug("connect_all_clusters: #{connected.size}/#{results.size} connected")
sync_vault_connected(connected.any?)
results
end
|
#connected_clusters ⇒ Object
41
42
43
|
# File 'lib/legion/crypt/vault_cluster.rb', line 41
def connected_clusters
clusters.select { |_, config| config[:token] && config[:connected] }
end
|
#default_cluster_name ⇒ Object
32
33
34
35
|
# File 'lib/legion/crypt/vault_cluster.rb', line 32
def default_cluster_name
name = vault_settings[:default]
name ? name.to_sym : clusters.keys.first
end
|
#vault_client(name = nil) ⇒ Object
21
22
23
24
25
|
# File 'lib/legion/crypt/vault_cluster.rb', line 21
def vault_client(name = nil)
name = resolve_cluster_name(name)
@vault_clients ||= {}
@vault_clients[name] ||= build_vault_client(clusters[name])
end
|