{"id":20329954,"url":"https://github.com/f5devcentral/f5-certificate-rotate","last_synced_at":"2025-03-04T12:20:29.624Z","repository":{"id":44548355,"uuid":"272555899","full_name":"f5devcentral/f5-certificate-rotate","owner":"f5devcentral","description":null,"archived":false,"fork":false,"pushed_at":"2022-06-22T18:21:22.000Z","size":16932,"stargazers_count":5,"open_issues_count":0,"forks_count":7,"subscribers_count":6,"default_branch":"master","last_synced_at":"2025-01-14T15:18:54.667Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"HCL","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/f5devcentral.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2020-06-15T22:22:43.000Z","updated_at":"2022-04-15T21:19:36.000Z","dependencies_parsed_at":"2022-09-10T05:21:19.673Z","dependency_job_id":null,"html_url":"https://github.com/f5devcentral/f5-certificate-rotate","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/f5devcentral%2Ff5-certificate-rotate","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/f5devcentral%2Ff5-certificate-rotate/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/f5devcentral%2Ff5-certificate-rotate/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/f5devcentral%2Ff5-certificate-rotate/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/f5devcentral","download_url":"https://codeload.github.com/f5devcentral/f5-certificate-rotate/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":241844788,"owners_count":20029721,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-14T20:14:13.039Z","updated_at":"2025-03-04T12:20:29.600Z","avatar_url":"https://github.com/f5devcentral.png","language":"HCL","funding_links":[],"categories":[],"sub_categories":[],"readme":"# F5 BIG-IP HashiCorp Vault Integration\n\nThis repo uses HashiCorp Vault to manage SSL Certificates\n\n# Architecture\n![Demo Arch](rtaImage.png)\n\n# What does the repo uses ?\n- Repo uses F5 BIG-IP VE Version 14.X \n- HashiCorp Vault 1.5\n\n# How to use Repo ?\n- Git Clone repo using ``` https://github.com/scshitole/bigip-vault.git ```\n- change directory ``` cd bigip-vault ```\n- deploy ``` terraform plan \u0026\u0026 terraform apply -auto-approve ```\n- This will deploy F5 BIG-IP intance \u0026 install Vault on ubuntu on AWS\n- SSH into the ubuntu server and cd/tmp\n- Configure vault and use vaul agent\n```\nexport VAULT_ADDR=http://127.0.0.1:8200\nexport VAULT_TOKEN=root\nvault write pki_int/roles/web-certs allowed_domains=demof5.com ttl=160s max_ttl=30m allow_subdomains=true \nvault auth enable approle\nvault policy write app-pol app-pol.hcl\nvault write auth/approle/role/web-certs policies=\"app-pol\"\nvault read -format=json auth/approle/role/web-certs/role-id | jq -r '.data.role_id' \u003e roleID\nvault write -f -format=json auth/approle/role/web-certs/secret-id | jq -r '.data.secret_id' \u003e secretID\nvault agent -config=agent-config.hcl -log-level=debug\n```\n- Open a new terminal and SSH into the ubuntu server again.\n- Run the command ``` bash stuff.sh ``` this will deploy the AS3 rpm  \u0026 VIP\n- Stop the vault agent and uncomment ``` command = \"bash updt.sh\" ``` in the file agent-config.hcl \n- Run ``` vault agent -config=agent-config.hcl -log-level=debug ``` to update the certs automatically\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ff5devcentral%2Ff5-certificate-rotate","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ff5devcentral%2Ff5-certificate-rotate","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ff5devcentral%2Ff5-certificate-rotate/lists"}