Pin openbao secrets plugins to exact versions (lockstep with catalog sha)

ensure: present/latest let the plugin binaries drift from the sha256 pinned in
the terraform-vault catalog (config/plugins/*.yaml); on the next OpenBao restart
a drifted binary fails the sha check and the plugin won't launch. Pin each to
the version whose binary matches its registered sha (all verified against the
RPMs):

- openbao-plugin-secrets-litellm: 0.1.1 (sha 2263ebcb…)
- openbao-plugin-secrets-gpg:     0.1.0 (sha 0e92d740…)
- openbao-plugin-secrets-rancher: 0.1.1 (sha 9e597cd9…; was ensure: latest)

openbao-plugins (base bundle) left unpinned.
This commit is contained in:
Ben Vincent
2026-07-20 23:42:05 +10:00
parent 206a4521e5
commit 4d112ad67f
+9 -3
View File
@@ -27,8 +27,14 @@ profiles::nginx::simpleproxy::proxy_port: 8200
profiles::nginx::simpleproxy::proxy_path: '/'
profiles::packages::include:
# openbao-plugins (base bundle) left unpinned; it tracks the openbao package.
openbao-plugins: {}
openbao-plugin-secrets-litellm: {}
openbao-plugin-secrets-gpg: {}
# Secrets plugins pinned to the exact version whose binary matches the sha256
# registered in terraform-vault (config/plugins/*.yaml). Bump both in lockstep
# on upgrade, or OpenBao refuses to launch the plugin after a restart.
openbao-plugin-secrets-litellm:
ensure: '0.1.1'
openbao-plugin-secrets-gpg:
ensure: '0.1.0'
openbao-plugin-secrets-rancher:
ensure: latest
ensure: '0.1.1'