vault/seal

certmanager acme challenge dns01 provider

Vault can optionally be configured to automatically unseal, using a cloud-based KMS. Currently the only configured option is "awskms", which necessitates you setting the following additional parameters

  • vault/awskms-region
  • vault/awskms-access-key
  • vault/awskms-secret-key
  • vault/awskms-kms-key-id