Conjur credential manager
Concourse can be configured to pull credentials from a CyberArk Conjur instance.
Configuration
To enable this credential manager, configure the following environment variables on the
web node:
CONCOURSE_CONJUR_APPLIANCE_URL=https://credhub-server:9000
CONCOURSE_CONJUR_ACCOUNT=db02de05-fa39-4855-059b-67221c5c2f63
CONCOURSE_CONJUR_AUTHN_LOGIN=6a174c20-f6de-a53c-74d2-6018fcceff64
CONCOURSE_CONJUR_AUTHN_API_KEY=6a174c20-f6de-a53c-74d2-6018fcceff64
Token File Configuration
Conjur can also be configured to use a token file instead of login and API keys by configuring the following environment variable:
TLS Configuration
If your Conjur instance is signed with TLS by a local Certificate Authority, you can use the following environment variable:
Permissions
The following is an example Conjur policy that can be used to grant permissions to a Conjur host. In this example
host/concourse will have permissions to read and update all the secrets within the TEAM_NAME
and PIPELINE_NAME policies.
- !host concourse
- !policy
id: concourse
owner: !host concourse
body:
- !policy
id: TEAM_NAME
body:
- !variable team-secret-variable
- !policy
id: PIPELINE_NAME
body:
- !variable pipeline-secret-variable
Note that the TEAM_NAME and PIPELINE_NAME text above should be replaced to fit your Concourse setup.
For more information on how to create and load Conjur policies, review the official documentation.
Credential Lookup Rules
When resolving a parameter such as ((foo_param)), it will look in the following paths, in order:
/concourse/TEAM_NAME/PIPELINE_NAME/foo_param/concourse/TEAM_NAME/foo_param
If the action is being run in the context of a pipeline (e.g. a check or a step in a build of a job), the ATC will
first look in the pipeline path. If it's not found there, it will look in the team path. This allows credentials to be
scoped widely if they're common across many pipelines.
When executing a one-off task, there is no pipeline: so in this case, only the team path /concourse/TEAM_NAME/foo is
searched.
There are several ways to customize the lookup logic:
- Change the team-, pipeline-, and absolute secret dependent path templates.
Each of these can be controlled by Concourse command line flags, or environment variables.
Changing the path templates
You can choose your own list of templates, which will expand to team-, pipeline-, and absolute secret specific paths. By default, the templates used are:
CONCOURSE_CONJUR_TEAM_SECRET_TEMPLATE="concourse/{{.Team}}/{{.Secret}}
CONCOURSE_CONJUR_PIPELINE_SECRET_TEMPLATE=/concourse/{{.Team}}/{{.Pipeline}}/{{.Secret}}
CONCOURSE_CONJUR_SECRET_TEMPLATE=vaultName/{{.Secret}}
When secrets are to be looked up, these are evaluated where {{.Team}} expands to the current team, {{.Pipeline}} to
the current pipeline (if any), and {{.Secret}} to the name of the secret. So if the settings are:
CONCOURSE_CONJUR_TEAM_SECRET_TEMPLATE="{{.Team}}/concourse/{{.Secret}}
CONCOURSE_CONJUR_PIPELINE_SECRET_TEMPLATE=/{{.Team}}/concourse/{{.Pipeline}}/{{.Secret}}
CONCOURSE_CONJUR_SECRET_TEMPLATE=conjur/{{.Secret}}
and ((password)) is used in team myteam and pipeline mypipeline, Concourse will look for the following, in order:
/myteam/concourse/mypipeline/password/myteam/concourse/password/conjur/password