LINUXOR.SK ... open source notes ...

Vault - vault-logs-s3-sync.sh (log shipping)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Audit logging and log shipping

noteThe script holds the S3 access key and secret key in clear text. They are placeholders here; on the hosts the file was readable by root only.

The script that copies rotated, compressed Vault audit logs to S3-compatible object storage once a day. aws s3 sync uploads only what the bucket does not have yet, so a missed day is caught up on the next run.

ItemValue
Path on the host/usr/local/bin/vault-logs-s3-sync.sh
Deployed onevery Vault node
Run by/etc/crontab, daily at 07:00, as root
NeedsAWS CLI v2 and the internal CA in the system trust store
Targetdirectory logs in the environment's bucket

The file

bash
#!/bin/bash

# Configuration of AWS CLI client
export AWS_ENDPOINT_URL=https://s3-a.example.net
export AWS_ACCESS_KEY_ID=<S3_ACCESS_KEY_ID>
export AWS_SECRET_ACCESS_KEY=<S3_SECRET_ACCESS_KEY>
export AWS_CA_BUNDLE=/etc/ssl/certs/ca-bundle.crt

# Synchronization of all files "*.log.gz" from directory "/var/log/vault" to directory "logs" in the S3 bucket "s3://prod-vault"
/usr/local/bin/aws s3 sync /var/log/vault s3://prod-vault/logs/ --exclude "*" --include "*.log.gz"
← solutionz