Docker-based 3-node containerized HA Vault cluster with LB hourly
Budget: $15 – $25 USD
Reading Time: less than 4mins (@150wpm), 572 words
+++ Who are we?
4 Devs (FE/BE), 1 Designer, 1 Product Lead & 1 Ops Lead building a PRE-REVENUE decentralized e-commerce marketplace as a bootstrapped startup.
+++ Who are we looking for?
DevOps Engineer experienced specifically with deploying, testing & setting policies for Docker Compose-based 3-node High Availability open-source version of Vault (Hashicorp) cluster on Linux (Ubuntu) nodes accessed via a load-balancing reverse proxy setup (also via a Docker container on Linux (Ubuntu).
+++ Your deliverables
Deploy 3-node High Availability Hashicorp Vault cluster with via Docker
Deploy a load-balancing reverse proxy (HAproxy or NGINX reverse proxy) with sticky sessions for the 3-nodes also via Docker
Ensure traffic between reverse proxy & Vault is encrypted via HTTPS (TLS/SSL) with SSL termination on both ends.
Implement health checks in reverse proxy config to route traffic to healthy Vault instances.
Test sample secrets & related paths, as well as read/write/admin policies & roles
Configure Vault to enable the audit log to log events to a file & setup log monitoring via a custom script (cron) to monitor the audit log for specific events (e.g.: a particular secret/policy change) so when script detects such an event, it sends a notification (e.g.: logs to file). If you’re capable, then connect this to Google Chat using Google Chat's API.
Document the process of completing all deliverables so they can be replicated from scratch by someone with limited Linux knowledge.
IMPORTANT Notes
Environment: Provided sudo-level SSH access to 3 Linux (Ubuntu) nodes
Critical that we setup from scratch using your docs to safeguard root tokens & unseal keys
If you’re using Consul as Vault’s storage backend, please use Consul’s service discovery to dynamically discover & route traffic to healthy Vault servers.
+++ Acceptance Criteria
We will follow your documentation to build from scratch the 3 node cluster with reverse load balancing proxy in Docker containers that delivers the above list
We can login directly to any of the Vault nodes, access & add secrets & policies
Any secret/path/policy on one node we add can be accessed from any other node.
We’ll degrade one node & still access any secret/path/policy via a CLI call to proxy
We’ll degrade two nodes & still access any secret/path/policy via a CLI call to proxy
We’ll degrade the 3rd node, wait & then restore the 1st and/or 2nd node & still access any secret/path/policy
We’ll be able to login to Vault using an OIDC (we’ll use Google)
We’ll be able to view the notification of a specific secret in the audit log and note that it has been output to a specific file (or to Google Chat, if you have done this integration).
+++ MINIMUM experience
Hashicorp Vault HA proxy config
Have built complex scripts to integrate Linux (Ubuntu/Debian) shell commands
Docker Compose and related YAML config & commands
Great documentation experience
+++ HOW TO APPLY
1. Send a message to express interest.
2. Please fill out the cost estimator located here: https://docs.google.com/spreadsheets/d/1sSQ8vXa6zEjaxbkpwMqt_V8Bgp7Gcx5_Hp63mzr3fJc/
+++ Will this be part of ongoing work?
We will have maintenance tasks & other jobs (e.g.: Keycloak deployment, offsite backup) where we’d use your services.
+++ Do we work with Agencies?
ONLY if we screen & work directly with the developer. As a startup, we have so little time to spare so intro calls or go-between managers don’t make sense.
We look forward to hearing from you. Thank you ?
+++ Who are we?
4 Devs (FE/BE), 1 Designer, 1 Product Lead & 1 Ops Lead building a PRE-REVENUE decentralized e-commerce marketplace as a bootstrapped startup.
+++ Who are we looking for?
DevOps Engineer experienced specifically with deploying, testing & setting policies for Docker Compose-based 3-node High Availability open-source version of Vault (Hashicorp) cluster on Linux (Ubuntu) nodes accessed via a load-balancing reverse proxy setup (also via a Docker container on Linux (Ubuntu).
+++ Your deliverables
Deploy 3-node High Availability Hashicorp Vault cluster with via Docker
Deploy a load-balancing reverse proxy (HAproxy or NGINX reverse proxy) with sticky sessions for the 3-nodes also via Docker
Ensure traffic between reverse proxy & Vault is encrypted via HTTPS (TLS/SSL) with SSL termination on both ends.
Implement health checks in reverse proxy config to route traffic to healthy Vault instances.
Test sample secrets & related paths, as well as read/write/admin policies & roles
Configure Vault to enable the audit log to log events to a file & setup log monitoring via a custom script (cron) to monitor the audit log for specific events (e.g.: a particular secret/policy change) so when script detects such an event, it sends a notification (e.g.: logs to file). If you’re capable, then connect this to Google Chat using Google Chat's API.
Document the process of completing all deliverables so they can be replicated from scratch by someone with limited Linux knowledge.
IMPORTANT Notes
Environment: Provided sudo-level SSH access to 3 Linux (Ubuntu) nodes
Critical that we setup from scratch using your docs to safeguard root tokens & unseal keys
If you’re using Consul as Vault’s storage backend, please use Consul’s service discovery to dynamically discover & route traffic to healthy Vault servers.
+++ Acceptance Criteria
We will follow your documentation to build from scratch the 3 node cluster with reverse load balancing proxy in Docker containers that delivers the above list
We can login directly to any of the Vault nodes, access & add secrets & policies
Any secret/path/policy on one node we add can be accessed from any other node.
We’ll degrade one node & still access any secret/path/policy via a CLI call to proxy
We’ll degrade two nodes & still access any secret/path/policy via a CLI call to proxy
We’ll degrade the 3rd node, wait & then restore the 1st and/or 2nd node & still access any secret/path/policy
We’ll be able to login to Vault using an OIDC (we’ll use Google)
We’ll be able to view the notification of a specific secret in the audit log and note that it has been output to a specific file (or to Google Chat, if you have done this integration).
+++ MINIMUM experience
Hashicorp Vault HA proxy config
Have built complex scripts to integrate Linux (Ubuntu/Debian) shell commands
Docker Compose and related YAML config & commands
Great documentation experience
+++ HOW TO APPLY
1. Send a message to express interest.
2. Please fill out the cost estimator located here: https://docs.google.com/spreadsheets/d/1sSQ8vXa6zEjaxbkpwMqt_V8Bgp7Gcx5_Hp63mzr3fJc/
+++ Will this be part of ongoing work?
We will have maintenance tasks & other jobs (e.g.: Keycloak deployment, offsite backup) where we’d use your services.
+++ Do we work with Agencies?
ONLY if we screen & work directly with the developer. As a startup, we have so little time to spare so intro calls or go-between managers don’t make sense.
We look forward to hearing from you. Thank you ?