---
title: Charmhub | Deploy Vault using Charmhub - The Open Operator Collection
description: Deploy the latest version of Vault on any cloud.
url: https://charmhub.io/vault/configurations
---

# Vault

[Vault charmers](https://charmhub.io/publisher/vault-charmers "View all packages from Vault charmers")

* [Vault charmers](https://charmhub.io/publisher/vault-charmers "View all packages from Vault charmers")
* [Security](https://charmhub.io/?filter=security)

Platform:

24.04

23.10

23.04

22.10

22.04

20.04

18.04

2.0/stable 710

```
juju deploy vault --channel 2.0/stable
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [access\_country\_name](https://charmhub.io/vault/configurations#access_country_name)
* [access\_email\_address](https://charmhub.io/vault/configurations#access_email_address)
* [access\_locality\_name](https://charmhub.io/vault/configurations#access_locality_name)
* [access\_organization](https://charmhub.io/vault/configurations#access_organization)
* [access\_organizational\_unit](https://charmhub.io/vault/configurations#access_organizational_unit)
* [access\_sans\_dns](https://charmhub.io/vault/configurations#access_sans_dns)
* [access\_sans\_ip](https://charmhub.io/vault/configurations#access_sans_ip)
* [access\_state\_or\_province\_name](https://charmhub.io/vault/configurations#access_state_or_province_name)
* [acme\_allow\_any\_name](https://charmhub.io/vault/configurations#acme_allow_any_name)
* [acme\_allow\_bare\_domains](https://charmhub.io/vault/configurations#acme_allow_bare_domains)
* [acme\_allow\_ip\_sans](https://charmhub.io/vault/configurations#acme_allow_ip_sans)
* [acme\_allow\_subdomains](https://charmhub.io/vault/configurations#acme_allow_subdomains)
* [acme\_allow\_wildcard\_certificates](https://charmhub.io/vault/configurations#acme_allow_wildcard_certificates)
* [acme\_allowed\_domains](https://charmhub.io/vault/configurations#acme_allowed_domains)
* [acme\_ca\_common\_name](https://charmhub.io/vault/configurations#acme_ca_common_name)
* [acme\_ca\_country\_name](https://charmhub.io/vault/configurations#acme_ca_country_name)
* [acme\_ca\_email\_address](https://charmhub.io/vault/configurations#acme_ca_email_address)
* [acme\_ca\_locality\_name](https://charmhub.io/vault/configurations#acme_ca_locality_name)
* [acme\_ca\_organization](https://charmhub.io/vault/configurations#acme_ca_organization)
* [acme\_ca\_organizational\_unit](https://charmhub.io/vault/configurations#acme_ca_organizational_unit)
* [acme\_ca\_sans\_dns](https://charmhub.io/vault/configurations#acme_ca_sans_dns)
* [acme\_ca\_state\_or\_province\_name](https://charmhub.io/vault/configurations#acme_ca_state_or_province_name)
* [acme\_country](https://charmhub.io/vault/configurations#acme_country)
* [acme\_locality](https://charmhub.io/vault/configurations#acme_locality)
* [acme\_organization](https://charmhub.io/vault/configurations#acme_organization)
* [acme\_organizational\_unit](https://charmhub.io/vault/configurations#acme_organizational_unit)
* [acme\_province](https://charmhub.io/vault/configurations#acme_province)
* [default\_lease\_ttl](https://charmhub.io/vault/configurations#default_lease_ttl)
* [log\_level](https://charmhub.io/vault/configurations#log_level)
* [logrotate\_frequency](https://charmhub.io/vault/configurations#logrotate_frequency)
* [max\_lease\_ttl](https://charmhub.io/vault/configurations#max_lease_ttl)
* [pki\_allow\_any\_name](https://charmhub.io/vault/configurations#pki_allow_any_name)
* [pki\_allow\_bare\_domains](https://charmhub.io/vault/configurations#pki_allow_bare_domains)
* [pki\_allow\_ip\_sans](https://charmhub.io/vault/configurations#pki_allow_ip_sans)
* [pki\_allow\_subdomains](https://charmhub.io/vault/configurations#pki_allow_subdomains)
* [pki\_allow\_wildcard\_certificates](https://charmhub.io/vault/configurations#pki_allow_wildcard_certificates)
* [pki\_allowed\_domains](https://charmhub.io/vault/configurations#pki_allowed_domains)
* [pki\_ca\_common\_name](https://charmhub.io/vault/configurations#pki_ca_common_name)
* [pki\_ca\_country\_name](https://charmhub.io/vault/configurations#pki_ca_country_name)
* [pki\_ca\_email\_address](https://charmhub.io/vault/configurations#pki_ca_email_address)
* [pki\_ca\_locality\_name](https://charmhub.io/vault/configurations#pki_ca_locality_name)
* [pki\_ca\_organization](https://charmhub.io/vault/configurations#pki_ca_organization)
* [pki\_ca\_organizational\_unit](https://charmhub.io/vault/configurations#pki_ca_organizational_unit)
* [pki\_ca\_sans\_dns](https://charmhub.io/vault/configurations#pki_ca_sans_dns)
* [pki\_ca\_state\_or\_province\_name](https://charmhub.io/vault/configurations#pki_ca_state_or_province_name)
* [pki\_country](https://charmhub.io/vault/configurations#pki_country)
* [pki\_locality](https://charmhub.io/vault/configurations#pki_locality)
* [pki\_organization](https://charmhub.io/vault/configurations#pki_organization)
* [pki\_organizational\_unit](https://charmhub.io/vault/configurations#pki_organizational_unit)
* [pki\_province](https://charmhub.io/vault/configurations#pki_province)
* [pki\_self\_signed\_ca\_validity](https://charmhub.io/vault/configurations#pki_self_signed_ca_validity)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* access\_country\_name | string

  The Vault charm will use this configuration option when requesting a certificate from a TLS provider using the `tls-certificates-access` charm relation interface. If not set, the Vault charm will request a certificate without this attribute.
* access\_email\_address | string

  The Vault charm will use this configuration option when requesting a certificate from a TLS provider using the `tls-certificates-access` charm relation interface. If not set, the Vault charm will request a certificate without this attribute.
* access\_locality\_name | string

  The Vault charm will use this configuration option when requesting a certificate from a TLS provider using the `tls-certificates-access` charm relation interface. If not set, the Vault charm will request a certificate without this attribute.
* access\_organization | string

  The Vault charm will use this configuration option when requesting a certificate from a TLS provider using the `tls-certificates-access` charm relation interface. If not set, the Vault charm will request a certificate without this attribute.
* access\_organizational\_unit | string

  The Vault charm will use this configuration option when requesting a certificate from a TLS provider using the `tls-certificates-access` charm relation interface. If not set, the Vault charm will request a certificate without this attribute.
* access\_sans\_dns | string

  The Vault charm will use this configuration option when requesting a certificate from a TLS provider using the `tls-certificates-access` charm relation interface. If not set, the Vault charm will automatically generate subject alternative names.
* access\_sans\_ip | string

  Comma-separated list of IP addresses to include as SANs for the access certificate. The Vault charm will use this configuration option when requesting a certificate from a TLS provider using the `tls-certificates-access` charm relation interface. These are in addition to IPs automatically detected by the charm.
* access\_state\_or\_province\_name | string

  The Vault charm will use this configuration option when requesting a certificate from a TLS provider using the `tls-certificates-access` charm relation interface. If not set, the Vault charm will request a certificate without this attribute.
* acme\_allow\_any\_name | boolean

  Allow the ACME server of Vault to issue certificates for any domain name. The Vault charm will use this configuration option in the context of acting as an intermediate CA.
* acme\_allow\_bare\_domains | boolean

  Default: True

  Specifies if clients can request certificates matching the value of the actual domains themselves. For example, if `allowed_domains` contains `example.com`, setting this to `true` allows clients to actually request a certificate for `example.com`.
* acme\_allow\_ip\_sans | boolean

  Allow the ACME server of Vault to issue certificates with IP Subject Alternative Names. The Vault charm will use this configuration option in the context of acting as an intermediate CA.
* acme\_allow\_subdomains | boolean

  Specifies if clients can request certificates with common names that are subdomains of the common name in the `allowed_domains` list. This includes wildcard subdomains. For example, an allowed\_domains value of `example.com` with this option set to `true` will allow `foo.example.com` and `fou.bar.example.com` as well as `*.example.com`.
* acme\_allow\_wildcard\_certificates | boolean

  Default: True

  Specifies if clients can request certificates certificates with RFC 6125 wildcards in the CN field. When set to False, Vault will not issue wildcards, even if they would've been allowed by another option. Vault supports the following four wildcard types: - `*.example.com`: a single wildcard as the entire left-most label - `foo*.example.com`: a single suffixed wildcard in the left-most label - `*foo.example.com`: a single prefixed wildcard in the left-most label - `f*o.example.com`: a single interior wildcard in the left-most label
* acme\_allowed\_domains | string

  A comma-separated list of domain names for which the Vault charm can sign certificates. The Vault charm will use this configuration option in the context of acting as an intermediate CA. Certificate requests for clients using the ACME server of Vault will need to use a domain name from this list.
* acme\_ca\_common\_name | string

  The Vault charm will use this configuration option when requesting a CA certificate from a TLS provider using the `tls-certificates-acme` charm relation interface. Requirers using the ACME server of Vault will receive signed certificates from that CA. This option is required when using the `tls-certificates-acme` charm relation interface.
* acme\_ca\_country\_name | string

  The Vault charm will use this configuration option when requesting a CA certificate from a TLS provider using the `tls-certificates-acme` charm relation interface. Requirers using the ACME server of Vault will receive signed certificates from that CA. If not set, the Vault charm will request a CA certificate without this attribute.
* acme\_ca\_email\_address | string

  The Vault charm will use this configuration option when requesting a CA certificate from a TLS provider using the `tls-certificates-acme` charm relation interface. Requirers using the ACME server of Vault will receive signed certificates from that CA. If not set, the Vault charm will request a CA certificate without this attribute.
* acme\_ca\_locality\_name | string

  The Vault charm will use this configuration option when requesting a CA certificate from a TLS provider using the `tls-certificates-acme` charm relation interface. Requirers using the ACME server of Vault will receive signed certificates from that CA. If not set, the Vault charm will request a CA certificate without this attribute.
* acme\_ca\_organization | string

  The Vault charm will use this configuration option when requesting a CA certificate from a TLS provider using the `tls-certificates-acme` charm relation interface. Requirers using the ACME server of Vault will receive signed certificates from that CA. If not set, the Vault charm will request a CA certificate without this attribute.
* acme\_ca\_organizational\_unit | string

  The Vault charm will use this configuration option when requesting a CA certificate from a TLS provider using the `tls-certificates-acme` charm relation interface. Requirers using the ACME server of Vault will receive signed certificates from that CA. If not set, the Vault charm will request a CA certificate without this attribute.
* acme\_ca\_sans\_dns | string

  Comma-separated list of DNS names for the CA certificate. The Vault charm will use this configuration option when requesting a CA certificate from a TLS provider using the `tls-certificates-acme` charm relation interface. Requirers using the ACME server of Vault will receive signed certificates from that CA. If not set, the Vault charm will automatically generate subject alternative names.
* acme\_ca\_state\_or\_province\_name | string

  The Vault charm will use this configuration option when requesting a CA certificate from a TLS provider using the `tls-certificates-acme` charm relation interface. Requirers using the ACME server of Vault will receive signed certificates from that CA. If not set, the Vault charm will request a CA certificate without this attribute.
* acme\_country | string

  This value specifies the C (Country) value in the Subject field of the certificate issued by Vault ACME. If not set the issued certificate will not have a C value in the Subject field.
* acme\_locality | string

  This value specifies the L (Locality) value in the Subject field of the certificate issued by Vault PKI. If not set the issued certificate will not have an L value in the Subject field.
* acme\_organization | string

  This value specifies the O (Organization) value in the Subject field of the certificate issued by Vault ACME. If not set the issued certificate will not have an O value in the Subject field.
* acme\_organizational\_unit | string

  This value specifies the OU (Organizational Unit) value in the Subject field of the certificate issued by Vault ACME. If not set the issued certificate will not have an OU value in the Subject field.
* acme\_province | string

  This value specifies the ST (State or Province) value in the Subject field of the certificate issued by Vault ACME. If not set the issued certificate will not have a ST value in the Subject field.
* default\_lease\_ttl | string

  Default: 168h

  Specifies the default lease duration for Vault's tokens and secrets.
* log\_level | string

  Default: info

  The log verbosity level. Supported values (in order of descending detail) are trace, debug, info, warn, and error.
* logrotate\_frequency | string

  Default: daily

  How often to rotate syslog (daily, weekly, monthly)
* max\_lease\_ttl | string

  Default: 720h

  Specifies the maximum possible lease duration for Vault's tokens and secrets.
* pki\_allow\_any\_name | boolean

  Allow the Vault charm to sign certificates coming from the `vault-pki` integration for any domain name. The Vault charm will use this configuration option in the context of acting as an intermediate CA.
* pki\_allow\_bare\_domains | boolean

  Default: True

  Specifies if clients can request certificates matching the exact value of the domains listed in `pki_allowed_domains` (or `pki_ca_common_name` if not set). For example, if `pki_allowed_domains` is `example.com`, this option allows issuing a certificate for `example.com` itself. When disabled, only subdomains (if `pki_allow_subdomains` is true) can be issued, not the base domain.
* pki\_allow\_ip\_sans | boolean

  Allow the Vault charm to sign requests with IP Subject Alternative Names. The Vault charm will use this configuration option in the context of acting as an intermediate CA.
* pki\_allow\_subdomains | boolean

  Specifies if clients can request certificates with common names that are subdomains of the common name in the `allowed_domains` list. This includes wildcard subdomains. For example, an allowed\_domains value of `example.com` with this option set to `true` will allow `foo.example.com` and `fou.bar.example.com` as well as `*.example.com`.
* pki\_allow\_wildcard\_certificates | boolean

  Default: True

  Specifies if clients can request certificates certificates with RFC 6125 wildcards in the CN field. When set to False, Vault will not issue wildcards, even if they would've been allowed by another option. Vault supports the following four wildcard types: - `*.example.com`: a single wildcard as the entire left-most label - `foo*.example.com`: a single suffixed wildcard in the left-most label - `*foo.example.com`: a single prefixed wildcard in the left-most label - `f*o.example.com`: a single interior wildcard in the left-most label
* pki\_allowed\_domains | string

  A comma-separated list of domain names for which the Vault charm can sign certificates. The Vault charm will use this configuration option in the context of acting as an intermediate CA. Certificate requests for charms integrating with Vault using the `vault-pki` integration will need to use a domain name from this list.
* pki\_ca\_common\_name | string

  The Vault charm will use this configuration option when requesting a CA certificate from a TLS provider using the `tls-certificates-pki` charm relation interface. Charms integrating to Vault using the `vault-pki` charm relation interface will receive signed certificates from that CA. This option is required when using the `tls-certificates-pki` charm relation interface.
* pki\_ca\_country\_name | string

  The Vault charm will use this configuration option when requesting a CA certificate from a TLS provider using the `tls-certificates-pki` charm relation interface. Charms integrating to Vault using the `vault-pki` charm relation interface will receive signed certificates from that CA. If not set, the Vault charm will request a CA certificate without this attribute.
* pki\_ca\_email\_address | string

  The Vault charm will use this configuration option when requesting a CA certificate from a TLS provider using the `tls-certificates-pki` charm relation interface. Charms integrating to Vault using the `vault-pki` charm relation interface will receive signed certificates from that CA. If not set, the Vault charm will request a CA certificate without this attribute.
* pki\_ca\_locality\_name | string

  The Vault charm will use this configuration option when requesting a CA certificate from a TLS provider using the `tls-certificates-pki` charm relation interface. Charms integrating to Vault using the `vault-pki` charm relation interface will receive signed certificates from that CA. If not set, the Vault charm will request a CA certificate without this attribute.
* pki\_ca\_organization | string

  The Vault charm will use this configuration option when requesting a CA certificate from a TLS provider using the `tls-certificates-pki` charm relation interface. Charms integrating to Vault using the `vault-pki` charm relation interface will receive signed certificates from that CA. If not set, the Vault charm will request a CA certificate without this attribute.
* pki\_ca\_organizational\_unit | string

  The Vault charm will use this configuration option when requesting a CA certificate from a TLS provider using the `tls-certificates-pki` charm relation interface. Charms integrating to Vault using the `vault-pki` charm relation interface will receive signed certificates from that CA. If not set, the Vault charm will request a CA certificate without this attribute.
* pki\_ca\_sans\_dns | string

  Comma-separated list of DNS names for the CA certificate. The Vault charm will use this configuration option when requesting a CA certificate from a TLS provider using the `tls-certificates-pki` charm relation interface. Charms integrating to Vault using the `vault-pki` charm relation interface will receive signed certificates from that CA. If not set, the Vault charm will automatically generate subject alternative names.
* pki\_ca\_state\_or\_province\_name | string

  The Vault charm will use this configuration option when requesting a CA certificate from a TLS provider using the `tls-certificates-pki` charm relation interface. Charms integrating to Vault using the `vault-pki` charm relation interface will receive signed certificates from that CA. If not set, the Vault charm will request a CA certificate without this attribute.
* pki\_country | string

  This value specifies the C (Country) value in the Subject field of the certificate issued by Vault PKI. If not set the issued certificate will not have a C value in the Subject field.
* pki\_locality | string

  This value specifies the L (Locality) value in the Subject field of the certificate issued by Vault PKI. If not set the issued certificate will not have an L value in the Subject field.
* pki\_organization | string

  This value specifies the O (Organization) value in the Subject field of the certificate issued by Vault PKI. If not set the issued certificate will not have an O value in the Subject field.
* pki\_organizational\_unit | string

  This value specifies the OU (Organizational Unit) value in the Subject field of the certificate issued by Vault PKI. If not set the issued certificate will not have an OU value in the Subject field.
* pki\_province | string

  This value specifies the ST (State or Province) value in the Subject field of the certificate issued by Vault PKI. If not set the issued certificate will not have a ST value in the Subject field.
* pki\_self\_signed\_ca\_validity | int

  Default: 87600

  The validity period in hours for the self-signed CA certificate when using Vault's built-in PKI without an external CA relation (tls-certificates-pki). Default is 87600 hours (10 years). This option is only used when the `tls-certificates-pki` relation is not present and `pki_ca_common_name` is configured.
