feat: vaultwarden-test 1.37.2 + vault-test 2.0.4 compose (loopback) [#769]

Workstation test lane. Vault dev-mode = in-memory, well-known dev
root token by design (not a credential). PKI experiments for #697
start here.

https://projects.knownelement.com/issues/769#note-4152
This commit is contained in:
2026-09-04 06:19:44 -05:00
parent dc6b466717
commit 13daaf398e
2 changed files with 31 additions and 0 deletions
+16
View File
@@ -0,0 +1,16 @@
# vault-test — HashiCorp Vault DEV server (in-memory; wipes on restart).
# TEST ONLY. Loopback bind. Root token is the well-known dev default
# ("root") — this is not a credential, by design. PKI experiments for
# #697 (SSH certs, k8s CA) happen against THIS instance first.
services:
vault:
image: hashicorp/vault:2.0.4
container_name: ukrrs-pfv-vault-test
ports:
- "127.0.0.1:8201:8200"
environment:
VAULT_DEV_ROOT_TOKEN_ID: "root"
VAULT_DEV_LISTEN_ADDRESS: "0.0.0.0:8200"
cap_add:
- IPC_LOCK
restart: unless-stopped
+15
View File
@@ -0,0 +1,15 @@
# vaultwarden-test — loopback test instance. Vaultwarden is the secrets SoR
# in prod (ruling #743); this instance exists for preprod-style testing only.
services:
vaultwarden:
image: vaultwarden/server:1.37.2
container_name: ukrrs-pfv-vaultwarden-test
ports:
- "127.0.0.1:8222:80"
volumes:
- vw-test-data:/data
environment:
DOMAIN: "http://127.0.0.1:8222"
restart: unless-stopped
volumes:
vw-test-data: