Ian Fijolek
0bd995ec2b
Rather than having Traefik handle cert fetching, instead it is delegated to a separate job so that multiple Traefik instances can share certs
24 lines
492 B
HCL
24 lines
492 B
HCL
resource "nomad_job" "traefik" {
|
|
jobspec = file("${path.module}/traefik.nomad")
|
|
}
|
|
|
|
resource "nomad_acl_policy" "treafik_secrets_certs_read" {
|
|
name = "traefik-secrets-certs-read"
|
|
description = "Read certs to secrets store"
|
|
rules_hcl = <<EOH
|
|
namespace "default" {
|
|
variables {
|
|
path "secrets/certs/*" {
|
|
capabilities = ["read"]
|
|
}
|
|
path "secrets/certs" {
|
|
capabilities = ["read"]
|
|
}
|
|
}
|
|
}
|
|
EOH
|
|
job_acl {
|
|
job_id = resource.nomad_job.traefik.id
|
|
}
|
|
}
|