Vault - /etc/hosts (local name resolution)
Vault Solution · Config document · referenced from Virtual machines and OS build, TLS, DNS and certificates
The hosts file of every PROD server. A Vault cluster that cannot resolve its own peers cannot form a quorum, so the names the cluster depends on are resolved locally and DNS is only the second source.
| Item | Value |
|---|---|
| Path on the host | /etc/hosts |
| Shown here | PROD |
| Deployed on | every server of the environment |
| Resolver order | files, then DNS |
The file
127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4 # BASTION 10.10.3.18 prod-vault-bastion1.example.net prod-vault-bastion1 # LOADBALANCERS 10.10.2.10 prod-vault-lb1.example.net prod-vault-lb1 10.10.2.11 prod-vault-lb2.example.net prod-vault-lb2 10.10.2.14 prod-vault.example.net prod-vault # VAULT NODES 10.10.1.34 prod-vault-node1.example.net prod-vault-node1 10.10.1.35 prod-vault-node2.example.net prod-vault-node2 10.10.1.36 prod-vault-node3.example.net prod-vault-node3 10.10.1.37 prod-vault-node4.example.net prod-vault-node4 10.10.1.38 prod-vault-node5.example.net prod-vault-node5 # COMMON VAULT 10.30.2.14 common-vault.example.net common-vault # SIEM logging 10.40.2.11 log-collector.example.net # S3 storage - site A 10.40.6.10 s3-a.example.net # S3 storage - site B 10.40.6.11 s3-b.example.net