部署S3存储型Vault失败,区域配置不匹配问题排查
Vault集成S3存储部署时区域不匹配问题排查
问题场景
尝试部署集成S3存储的Vault服务,S3桶位于us-west-2区域,使用以下Kubernetes清单:
kind: ConfigMap apiVersion: v1 metadata: name: vault-config namespace: backend-shared labels: app: vault data: config.json: | { "listener": [ { "tcp": { "address": "0.0.0.0:8200", "tls_disable": true } } ], "storage": { "s3": { "bucket" : "vault-qa-storage" "region" : "us-west-2" "access_key" : "***" "secret_key" : "***+***+p" } }, "ui": true, "api_addr" : "http://0.0.0.0:8200" "max_lease_ttl" : "10h" "default_lease_ttl" : "7200h" "cluster_name" : "vault" "raw_storage_endpoint" : true "disable_sealwrap" : true "disable_printable_check" : true } --- kind: ConfigMap apiVersion: v1 metadata: name: vault-policy namespace: backend-shared labels: app: vault data: policy.json: | path "root-ca/issue/*" { capabilities = ["create", "read", "update"] } --- kind: Deployment apiVersion: apps/v1 metadata: name: vault namespace: backend-shared labels: app: vault spec: replicas: 1 selector: matchLabels: app: vault strategy: type: RollingUpdate rollingUpdate: maxSurge: 1 maxUnavailable: 1 template: metadata: labels: app: vault spec: containers: - name: vault image: vault:1.13.3 imagePullPolicy: Always command: ["vault", "server", "-config", "/vault/config/config.json"] securityContext: capabilities: add: - IPC_LOCK env: - name: VAULT_ADDR value: 'http://127.0.0.1:8200' - name: VAULT_API_ADDR value: 'http://127.0.0.1:8200' - name: VAULT_TOKEN valueFrom: secretKeyRef: name: vault key: root-token - name: VAULT_KEY valueFrom: secretKeyRef: name: vault key: unseal-key volumeMounts: - name: vault-config mountPath: /vault/config/config.json subPath: config.json - name: vault-policy mountPath: /vault/policy/policy.json subPath: policy.json ports: - name: vault containerPort: 8200 volumes: - name: vault-config configMap: name: vault-config items: - key: config.json path: config.json - name: vault-policy configMap: name: vault-policy items: - key: policy.json path: policy.json
部署时出现以下错误:
Error initializing storage of type s3: unable to access bucket "vault-qa-storage" in region "us-east-1": AuthorizationHeaderMalformed: The authorization header is malformed; the region 'us-east-1' is wrong; expecting 'us-west-2'
status code: 400, request id: HM2B4QHRT135ABBG, host id: 7igfngKalcSYfNIZKP5egnPfaE8MP/9yUysRAGBMdorS/Tsyo+/u0Wt/y7zOq6YG5luTR0+R0kE=
问题原因
你的config.json存在JSON语法错误:多个键值对末尾缺少逗号,导致Vault无法正确解析配置文件,进而无法读取你指定的us-west-2区域配置,最终使用了S3的默认区域us-east-1,引发授权头区域不匹配的错误。
具体错误位置:
storage.s3块内的bucket、region、access_key末尾都没有逗号- 顶层的
api_addr、max_lease_ttl等键值对末尾也缺少逗号
解决方案
- 修正JSON语法错误:给每个键值对末尾添加逗号(最后一个键值对除外)
- 敏感信息优化:不要将AWS的
access_key和secret_key明文写在ConfigMap中,改用Kubernetes Secret存储,避免敏感信息泄露
修正后的config.json示例
{ "listener": [ { "tcp": { "address": "0.0.0.0:8200", "tls_disable": true } } ], "storage": { "s3": { "bucket" : "vault-qa-storage", "region" : "us-west-2", "access_key" : "***", "secret_key" : "***+***+p" } }, "ui": true, "api_addr" : "http://0.0.0.0:8200", "max_lease_ttl" : "10h", "default_lease_ttl": "7200h", "cluster_name" : "vault", "raw_storage_endpoint" : true, "disable_sealwrap" : true, "disable_printable_check" : true }
敏感信息迁移到Secret的示例
创建存储AWS密钥的Secret:
apiVersion: v1 kind: Secret metadata: name: vault-aws-creds namespace: backend-shared type: Opaque data: access_key: <base64编码的access_key> secret_key: <base64编码的secret_key>
然后修改Vault的Deployment,通过环境变量注入密钥,同时从config.json中移除明文密钥:
- 在容器
env中添加:
- name: AWS_ACCESS_KEY_ID valueFrom: secretKeyRef: name: vault-aws-creds key: access_key - name: AWS_SECRET_ACCESS_KEY valueFrom: secretKeyRef: name: vault-aws-creds key: secret_key
config.json的s3块改为:
"s3": { "bucket" : "vault-qa-storage", "region" : "us-west-2" }
内容的提问来源于stack exchange,提问作者rp346
相关产品推荐
相关产品推荐

