151 lines
3.8 KiB
Markdown
151 lines
3.8 KiB
Markdown
[Documentation](../../README.md#documentation) → [Configuration](../config.en.md) → Security Parameters
|
|
|
|
-----
|
|
|
|
[Читать на русском](security.ru.md)
|
|
|
|
# Security Parameters
|
|
|
|
These parameters affect your Vitastor installation security and apply to OSDs, monitors and clients.
|
|
|
|
Most of them can be set in /etc/vitastor/vitastor.conf and in etcd, but don't support online modification.
|
|
|
|
- [etcd_client_cert](#etcd_client_cert)
|
|
- [etcd_client_key](#etcd_client_key)
|
|
- [etcd_ca](#etcd_ca)
|
|
- [osd_etcd_client_cert](#osd_etcd_client_cert)
|
|
- [osd_etcd_client_key](#osd_etcd_client_key)
|
|
- [mon_etcd_client_cert](#mon_etcd_client_cert)
|
|
- [mon_etcd_client_key](#mon_etcd_client_key)
|
|
- [vault_url](#vault_url)
|
|
- [vault_secret_api_path](#vault_secret_api_path)
|
|
- [vault_client_cert](#vault_client_cert)
|
|
- [vault_client_key](#vault_client_key)
|
|
- [vault_ca](#vault_ca)
|
|
- [vault_timeout_ms](#vault_timeout_ms)
|
|
- [vault_error_timeout_sec](#vault_error_timeout_sec)
|
|
- [vault_refresh_leeway_sec](#vault_refresh_leeway_sec)
|
|
- [max_aes_xts_pool_size](#max_aes_xts_pool_size)
|
|
|
|
## etcd_client_cert
|
|
|
|
- Type: string
|
|
|
|
Client TLS certificate to use for Vitastor client (not OSD and not monitor)
|
|
etcd https connections. May be path to a file or just a PEM string with certificate.
|
|
In the latter case, string must begin with "-----BEGIN CERTIFICATE-----".
|
|
|
|
## etcd_client_key
|
|
|
|
- Type: string
|
|
|
|
Private key for etcd_client_cert (also a file or a PEM string).
|
|
|
|
## etcd_ca
|
|
|
|
- Type: string
|
|
|
|
Trusted TLS CA to verify etcd server certificate. May be path to a file,
|
|
directory or just a PEM string with certificate.
|
|
|
|
## osd_etcd_client_cert
|
|
|
|
- Type: string
|
|
|
|
Same as [etcd_client_cert](#etcd_client_cert), but only for OSDs.
|
|
OSDs, clients and monitors should have different permissions, so they should
|
|
use different certificates.
|
|
|
|
## osd_etcd_client_key
|
|
|
|
- Type: string
|
|
|
|
Same as [etcd_client_key](#etcd_client_key), but only for OSDs.
|
|
|
|
## mon_etcd_client_cert
|
|
|
|
- Type: string
|
|
|
|
Same as [etcd_client_cert](#etcd_client_cert), but only for Vitastor monitors.
|
|
|
|
## mon_etcd_client_key
|
|
|
|
- Type: string
|
|
|
|
Same as [etcd_client_key](#etcd_client_key), but only for Vitastor monitors.
|
|
|
|
## vault_url
|
|
|
|
- Type: string
|
|
|
|
Vault base URL.
|
|
|
|
Vitastor clients support AES-256-XTS image data encryption with different per-image keys.
|
|
Encryption is performed by the client, OSDs don't have access to decrypted data.
|
|
|
|
Encryption keys may be stored in etcd or, for the increased security level, in an external
|
|
[HashiCorp Vault](https://developer.hashicorp.com/vault/) or [OpenBao](https://openbao.org/)
|
|
instance.
|
|
|
|
Vitastor clients use [v1 k/v secrets engine](https://openbao.org/api-docs/secret/kv/kv-v1/)
|
|
and [TLS authentication engine](https://openbao.org/api-docs/auth/cert/) in Vault.
|
|
|
|
In that case, only key IDs are stored in etcd.
|
|
|
|
## vault_secret_api_path
|
|
|
|
- Type: string
|
|
- Default: /v1/secret/
|
|
|
|
Vault v1 secret API mount path to use.
|
|
|
|
## vault_client_cert
|
|
|
|
- Type: string
|
|
|
|
Client TLS certificate to use for Vault connections. Just like [etcd_client_cert](#etcd_client_cert),
|
|
may be path to a file or just a certificate in PEM string.
|
|
|
|
## vault_client_key
|
|
|
|
- Type: string
|
|
|
|
Private key for vault_client_cert (also a file or a PEM string).
|
|
|
|
## vault_ca
|
|
|
|
- Type: string
|
|
|
|
Trusted TLS CA to verify Vault server certificate. May be path to a file,
|
|
directory or just a PEM string with certificate.
|
|
|
|
## vault_timeout_ms
|
|
|
|
- Type: integer
|
|
- Default: 5000
|
|
|
|
Timeout for Vault requests in milliseconds.
|
|
|
|
## vault_error_timeout_sec
|
|
|
|
- Type: integer
|
|
- Default: 60
|
|
|
|
Time (in seconds) to wait before retrying after receiving an error from Vault.
|
|
|
|
## vault_refresh_leeway_sec
|
|
|
|
- Type: integer
|
|
- Default: 60
|
|
|
|
Extra time (in seconds) before real Vault token lease_timeout to refresh it, just
|
|
in case of system clock drift.
|
|
|
|
## max_aes_xts_pool_size
|
|
|
|
- Type: integer
|
|
- Default: 256
|
|
|
|
Maximum number of OpenSSL encryption contexts cached in OSD memory. Probably
|
|
doesn't require modification.
|