Install aapm-service
aapm-service provides direct secret lookup via HTTP requests. Parameters:
aapm-service Parameters | |
|---|---|
Parameter | Meaning |
agent.service | The Agent's in-cluster DNS address (<agent-service>.<namespace>.svc.cluster.local). |
agent.port | The Agent's gRPC port. |
pam.url | The fallback (direct-to-Kron PAM) address used if the gRPC connection fails. Must be valid/reachable. |
agent.ignoreCertificate | Must be true if the Agent's own gRPC server uses a self-signed certificate. |
interceptor.ignoreCertificate | false is sufficient if Kron PAM has a publicly trusted certificate. |
vault.allowedAccounts[].accountName | The Kron PAM account name allowed to be accessed via the /vault endpoint (whitelist). |
vault.allowedAccounts[].accountPath | The path of the allowed account within Kron PAM. |
If agent.ignoreCertificate=false is left as-is, the service starts but /vault requests fail with PKIX path building failed (the Agent's self-signed certificate cannot be validated). This value must be true.
helm install aapm-service kron-pam/aapm-service \
--namespace kron-pam-aapm \
--create-namespace \
--set agent.service="kron-aapm-agent.ns-agent.svc.cluster.local" \
--set agent.port="8080" \
--set pam.url="https://<KRON_PAM_SERVER_ADDRESS>" \
--set agent.ignoreCertificate=true \
--set interceptor.ignoreCertificate=false \
--set "vault.allowedAccounts[0].accountName=<ACCOUNT_NAME>" \
--set "vault.allowedAccounts[0].accountPath=<ACCOUNT_PATH>"Verification
kubectl get pods -n kron-pam-aapm
kubectl logs -n kron-pam-aapm deploy/aapm-service --tail=40Success criteria: Pod is 1/1 Running, logs show Tomcat started on port 8443 (http) and Started AapmApplication in N seconds.