Vault - vault-logs-s3-sync.sh (log shipping)
Vault Solution · Config document · referenced from Audit logging and log shipping
noteThe script holds the S3 access key and secret key in clear text. They are placeholders here; on the hosts the file was readable by root only.
The script that copies rotated, compressed Vault audit logs to S3-compatible object storage once a day. aws s3 sync uploads only what the bucket does not have yet, so a missed day is caught up on the next run.
| Item | Value |
|---|---|
| Path on the host | /usr/local/bin/vault-logs-s3-sync.sh |
| Deployed on | every Vault node |
| Run by | /etc/crontab, daily at 07:00, as root |
| Needs | AWS CLI v2 and the internal CA in the system trust store |
| Target | directory logs in the environment's bucket |
The file
#!/bin/bash # Configuration of AWS CLI client export AWS_ENDPOINT_URL=https://s3-a.example.net export AWS_ACCESS_KEY_ID=<S3_ACCESS_KEY_ID> export AWS_SECRET_ACCESS_KEY=<S3_SECRET_ACCESS_KEY> export AWS_CA_BUNDLE=/etc/ssl/certs/ca-bundle.crt # Synchronization of all files "*.log.gz" from directory "/var/log/vault" to directory "logs" in the S3 bucket "s3://prod-vault" /usr/local/bin/aws s3 sync /var/log/vault s3://prod-vault/logs/ --exclude "*" --include "*.log.gz"