make vault.hcl root-only, LP:1695947

This commit is contained in:
Paul Collins 2017-06-13 09:15:29 +12:00
parent d4e6f3631d
commit 5e72664490
1 changed files with 1 additions and 1 deletions

View File

@ -67,7 +67,7 @@ def configure_vault(psql):
'ssl_available': is_state('vault.ssl.available'),
}
status_set('maintenance', 'creating vault config')
render('vault.hcl.j2', '/var/snap/vault/common/vault.hcl', context, perms=0o644)
render('vault.hcl.j2', '/var/snap/vault/common/vault.hcl', context, perms=0o600)
status_set('maintenance', 'creating vault unit file')
render('vault.service.j2', '/etc/systemd/system/vault.service', {}, perms=0o644)
status_set('maintenance', 'starting vault')