Pin openbao secrets plugins to exact versions (lockstep with catalog sha)
ensure: present/latest let the plugin binaries drift from the sha256 pinned in the terraform-vault catalog (config/plugins/*.yaml); on the next OpenBao restart a drifted binary fails the sha check and the plugin won't launch. Pin each to the version whose binary matches its registered sha (all verified against the RPMs): - openbao-plugin-secrets-litellm: 0.1.1 (sha 2263ebcb…) - openbao-plugin-secrets-gpg: 0.1.0 (sha 0e92d740…) - openbao-plugin-secrets-rancher: 0.1.1 (sha 9e597cd9…; was ensure: latest) openbao-plugins (base bundle) left unpinned.
This commit is contained in:
@@ -27,8 +27,14 @@ profiles::nginx::simpleproxy::proxy_port: 8200
|
||||
profiles::nginx::simpleproxy::proxy_path: '/'
|
||||
|
||||
profiles::packages::include:
|
||||
# openbao-plugins (base bundle) left unpinned; it tracks the openbao package.
|
||||
openbao-plugins: {}
|
||||
openbao-plugin-secrets-litellm: {}
|
||||
openbao-plugin-secrets-gpg: {}
|
||||
# Secrets plugins pinned to the exact version whose binary matches the sha256
|
||||
# registered in terraform-vault (config/plugins/*.yaml). Bump both in lockstep
|
||||
# on upgrade, or OpenBao refuses to launch the plugin after a restart.
|
||||
openbao-plugin-secrets-litellm:
|
||||
ensure: '0.1.1'
|
||||
openbao-plugin-secrets-gpg:
|
||||
ensure: '0.1.0'
|
||||
openbao-plugin-secrets-rancher:
|
||||
ensure: latest
|
||||
ensure: '0.1.1'
|
||||
|
||||
Reference in New Issue
Block a user