Skip to content

Instantly share code, notes, and snippets.

@avoidik
avoidik / pki-setup.sh
Created May 18, 2018 10:24 — forked from chrishoffman/pki-setup.sh
Vault Multi-Level CA Setup
vault mount pki
vault mount -path=pki1 pki
vault mount -path=pki2 pki
vault mount -path=pki3 pki
vault mount-tune -max-lease-ttl=87600h pki
vault mount-tune -max-lease-ttl=87600h pki1
vault mount-tune -max-lease-ttl=87600h pki2
vault mount-tune -max-lease-ttl=87600h pki3
vault write pki/root/generate/internal common_name="Vault Testing Root Authority" ttl=87600h
@avoidik
avoidik / cleanup.sh
Created June 8, 2018 10:21 — forked from flosell/cleanup.sh
This gist reproduces hashicorp/vault#3368
#!/usr/bin/env bash
function echob() {
echo -e "\033[1m$1\033[0m"
}
function delete_user() {
local username="$1"
echo "deleting ${username}"
aws iam delete-access-key --user-name ${username} --access-key-id $(jq -r .AccessKey.AccessKeyId ${username}-credentials.json)
aws iam delete-user --user-name ${username}
@avoidik
avoidik / configmap.yml
Created June 14, 2018 06:21 — forked from j18e/configmap.yml
Concourse on AWS Kubernetes Deployment with HTTPS endpoint
---
apiVersion: v1
kind: ConfigMap
metadata:
name: concourse-keys
data:
authorized_worker_keys: |+
ssh-rsa {{public_key_text}} worker-key
session_signing_key: |+
-----BEGIN RSA PRIVATE KEY-----
@avoidik
avoidik / gist:88dca6d5d8f66d25d4157f6563af78a2
Created June 21, 2018 10:28
Visual Studio Build Tools 14
http://go.microsoft.com/fwlink/?LinkId=691126&fixForIE=.exe
http://web.archive.org/web/20170519122327/http://landinghub.visualstudio.com:80/visual-cpp-build-tools
@avoidik
avoidik / gist:f0ae45f4d91149556c5842e21b7065d2
Last active February 22, 2019 16:17
Install Will on Windows
  • visual studio is required (here)
  • python for windows is required
  • from command-line (check path to stdint.h first)
pip install -U setuptools wheel virtualenv
virtualenv venv
venv\Scripts\activate.bat
set CL=-FI"%VCINSTALLDIR%\Tools\MSVC\14.14.26428\include\stdint.h"
pip install will
@avoidik
avoidik / barbershop.go
Last active September 21, 2018 05:57
Experiments with Go
package main
import (
"fmt"
"math/rand"
"sync"
"time"
)
// try to play with constants
#!/usr/bin/env sh
docker-machine rm -f rancher host1
docker-machine create rancher --driver virtualbox --virtualbox-cpu-count "-1" --virtualbox-disk-size "8000" --virtualbox-memory "512" --virtualbox-boot2docker-url=https://github.com/boot2docker/boot2docker/releases/download/v1.11.2/boot2docker.iso
docker-machine scp scripts/rancher-net.sh rancher:.
docker-machine ssh rancher sh rancher-net.sh
docker-machine regenerate-certs rancher -f
eval $(docker-machine env rancher)
docker-compose up -d
eval $(docker-machine env -u)
docker-machine create host1 --driver virtualbox --virtualbox-cpu-count "-1" --virtualbox-disk-size "54000" --virtualbox-memory "2048" --virtualbox-boot2docker-url=https://github.com/boot2docker/boot2docker/releases/download/v1.11.2/boot2docker.iso
@avoidik
avoidik / vault-token-role-via-api.sh
Created August 21, 2018 11:05 — forked from greenbrian/vault-token-role-via-api.sh
HashiCorp Vault Token Role overview
# start vault in dev mode
VAULT_UI=true vault server -dev -dev-root-token-id="password"
# write some secrets for our example usage
curl --request POST \
--silent \
--header "X-Vault-Token: password" \
--header "Content-Type: application/json" \
--data '{ "options": { "cas": 0 }, "data": { "username": "administrator", "password": "hunter2" } }' \
http://127.0.0.1:8200/v1/secret/data/dev | jq '.'
@avoidik
avoidik / README.md
Created August 21, 2018 18:41 — forked from joelthompson/README.md
Vault Auth
@avoidik
avoidik / get_vault_secret.py
Created August 21, 2018 18:45 — forked from edjackson-wf/get_vault_secret.py
IAM auth to Hashicorp Vault server from an ECS container
#!/usr/bin/env python3
import base64
import json
import requests
from aws_requests_auth.boto_utils import BotoAWSRequestsAuth
"""
This code will connect from an ECS container to a remote Hashicorp Vault server
and authenticate using the 'iam' auth_type for the AWS auth backend.