Docker-based 3-node containerized HA Vault cluster with LB hourly

Job ID: 37632077

Budget: $15 – $25 USD

Reading Time: less than 4mins (@150wpm), 572 words

+++ Who are we?

4 Devs (FE/BE), 1 Designer, 1 Product Lead & 1 Ops Lead building a PRE-REVENUE decentralized e-commerce marketplace as a bootstrapped startup.

+++ Who are we looking for?

DevOps Engineer experienced specifically with deploying, testing & setting policies for Docker Compose-based 3-node High Availability open-source version of Vault (Hashicorp) cluster on Linux (Ubuntu) nodes accessed via a load-balancing reverse proxy setup (also via a Docker container on Linux (Ubuntu).

+++ Your deliverables

Deploy 3-node High Availability Hashicorp Vault cluster with via Docker

Deploy a load-balancing reverse proxy (HAproxy or NGINX reverse proxy) with sticky sessions for the 3-nodes also via Docker

Ensure traffic between reverse proxy & Vault is encrypted via HTTPS (TLS/SSL) with SSL termination on both ends.

Implement health checks in reverse proxy config to route traffic to healthy Vault instances.

Test sample secrets & related paths, as well as read/write/admin policies & roles

Configure Vault to enable the audit log to log events to a file & setup log monitoring via a custom script (cron) to monitor the audit log for specific events (e.g.: a particular secret/policy change) so when script detects such an event, it sends a notification (e.g.: logs to file). If you’re capable, then connect this to Google Chat using Google Chat's API.

Document the process of completing all deliverables so they can be replicated from scratch by someone with limited Linux knowledge.

IMPORTANT Notes

Environment: Provided sudo-level SSH access to 3 Linux (Ubuntu) nodes

Critical that we setup from scratch using your docs to safeguard root tokens & unseal keys

If you’re using Consul as Vault’s storage backend, please use Consul’s service discovery to dynamically discover & route traffic to healthy Vault servers.

+++ Acceptance Criteria

We will follow your documentation to build from scratch the 3 node cluster with reverse load balancing proxy in Docker containers that delivers the above list

We can login directly to any of the Vault nodes, access & add secrets & policies

Any secret/path/policy on one node we add can be accessed from any other node.

We’ll degrade one node & still access any secret/path/policy via a CLI call to proxy

We’ll degrade two nodes & still access any secret/path/policy via a CLI call to proxy

We’ll degrade the 3rd node, wait & then restore the 1st and/or 2nd node & still access any secret/path/policy

We’ll be able to login to Vault using an OIDC (we’ll use Google)

We’ll be able to view the notification of a specific secret in the audit log and note that it has been output to a specific file (or to Google Chat, if you have done this integration).

+++ MINIMUM experience

Hashicorp Vault HA proxy config

Have built complex scripts to integrate Linux (Ubuntu/Debian) shell commands

Docker Compose and related YAML config & commands

Great documentation experience

+++ HOW TO APPLY

1. Send a message to express interest.

2. Please fill out the cost estimator located here: https://docs.google.com/spreadsheets/d/1sSQ8vXa6zEjaxbkpwMqt_V8Bgp7Gcx5_Hp63mzr3fJc/

+++ Will this be part of ongoing work?

We will have maintenance tasks & other jobs (e.g.: Keycloak deployment, offsite backup) where we’d use your services.

+++ Do we work with Agencies?

ONLY if we screen & work directly with the developer. As a startup, we have so little time to spare so intro calls or go-between managers don’t make sense.

We look forward to hearing from you. Thank you ?
Related categories: Ubuntu Network Administration Docker Compose