HashiCorp Vault + Certificate Automation Fix

Job ID: 39814641

Budget: $15 – $25 USD

We are running HashiCorp Vault in an air-gapped environment and need help fixing two issues:

Rundeck Integration

Currently, every time Rundeck restarts, we must manually regenerate a static Vault token and update the Rundeck properties file. This is bad practice — we want a proper authentication method (AppRole, approle with wrapped secret, or another secure approach) so that Rundeck can authenticate without static tokens.

Certificate Management

We use Vault + certbot for certificate management with Nginx on services like Zabbix, GitLab, Opsidian, and Rundeck.
In practice, it does not seem to work. Example: our Zabbix SSL cert expired at the end of August, causing service disruption. We need a reliable way to automate and renew internal certificates in the air-gapped setup.

Deliverables:

Update Vault + Rundeck integration to use a secure token flow (no static manual token).
Fix or redesign certificate management so certs for all apps renew properly in our environment.

Provide documentation of the changes and how to maintain them.

Environment:
Rocky 9 servers
Vault already deployed
Services: Zabbix, GitLab, Opsidian, Rundeck
Certificates managed with Nginx
Related categories: PHP Linux Apache Nginx Ubuntu DevOps Automation Ansible SSL Terraform