I have a working vault cluster, but I'm starting to do the final hardening steps by introducing TLS and have come to the conclusion that ... well ... vault best practices here are exceedingly vague as to both what dns names a certificate will need as well as what the various "ADDR" addresses do. it gets especially confusing in regards to consul, which as I read more seems to be used a backend only and should NOT be used for SD of vault itself.
At any rate the more I research, the more I stumble on parameters/variables that are either exceedingly vague in their purpose or flat out undocumented. Then there's settings that seem like they SHOULD exist but don't? Oh fun days.
Quick rundown of settings I've stumbled on but that I feel are poorly defined or completely omitted when compared to here:
VAULT_ADDR: this is obviously used by clients/agents to find the vault cluster ... but does the cluster need this defined? it's nowhere on the configuration page, yet shouldn't I need to advertise the main cluster url or no?
VAULT_API_ADDR: this is to advertise a unique URL to other vault members so they know who to redirect clients to. It also looks like it is MUST be present in the Certificate if you wish to use TLS.
VAULT_CLUSTER_ADDR: another redirect, but in this case it's a more generic server forwarding that will auto match the API address unless overridden. Honestly this may be wrong, but if true it's only because I went to a completely unique page to figure that out:
https://www.vaultproject.io/docs/concepts/ha.html. So this _might_ be additional SAN entries depending. But we're not done ...
VAULT_REDIRECT_ADDR: here's one that doesn't exist at all in either docs, but it turns out it's critical for HA use, the system will simply attempt to generate a value if it's missing, see the conversation
here: https://github.com/hashicorp/vault/issues/1337. But how is it unique from the other two? I mean ... at this point api is for clients, cluster is for servers (even though it states they prefer to chat through the back-end storage) and now we have this seemingly important value that is being auto set to ... something. If you're using Consul you probably need to hardcode this to IP, otherwise Consul will try to use multiple CNAMES for the vault service which will break dns resolution.
Oh and which of these need TLS? All of them I assume (though I also assume much of this has overlaps). What of consul address or it's active.vault.service.consul and standby.service.consul entries? Does the vault service even care to be aware of it's default service name or as long as the name in TLS it takes it?
My _suspicion_ to all the above is as follows:
VAULT_ADDR is a client only thing, I can pull that environment variable and the server wont care.
API/CLUSER_ADDR are for clients vs the internal cluster. All of these DNS names should be in the certificate (or IP if that's how they are referenced) and if they are unique is completely dependant on how I configure my servers.
REDIRECT_ADDR ... is ... uh ... apparently important but I can't find any definitive info on how it should be set vs. API/CLUSTER.
Do I need to set the generic vault name somewhere? basically the server equivalent to VAULT_ADDR? Or does vault not care as long as TLS works?