Unseal Vault

Work in Progress: This role is unfinished and untested.

This role unseals an initialized but sealed Vault server. The unseal key shares can be provided as:

  • A variable array of keys
  • A variable array of file paths to the keys on the remote filesystem
  • Secrets from Bitwarden

Variables

VariableDescriptionTypeDefault
unseal_vault_portConfigured Vault portint8200
unseal_vault_addrVault HTTP addressstringhttp://localhost:8200
unseal_storeAccepts file, bitwardenstring
unseal_keys_filesArray of files with unseal keyslist
unseal_keysArray of key shareslist
unseal_bw_passwordBitwarden passwordstring
unseal_bw_keys_namesList of Bitwarden secrets storing key shareslist