7e1f2c336c
## Why The new `openbao-plugin-secrets-arrstack` OpenBao secrets engine mints dynamic per-service arrproxy machine tokens for the arrstack (Sonarr/Radarr/Prowlarr) fleet. Its v0.1.0 RPM is now published in artifactapi (rpm-internal), so the OpenBao VM nodes can install the plugin binary into `/opt/openbao-plugins`. ## Changes - Add `openbao-plugin-secrets-arrstack` pinned to `0.1.0` to `profiles::packages::include` in `hieradata/roles/infra/storage/vault.yaml`, matching the existing pinned sibling plugins (litellm, gpg, rancher, gitea, apptoken, netbox, ghp). This PR only installs the RPM binary on the nodes. Catalog registration is handled separately by terraform-vault (`config/plugins/*.yaml`). ## Reference Plugin binary sha256 (used by the terraform-vault catalog registration, separate PR): ``` f8ee60ca7ba14819976acb7dc4cfb6799e3e8da8f871d0bb2bd18d1d9e537972 ``` Reviewed-on: #521 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
51 lines
1.7 KiB
YAML
51 lines
1.7 KiB
YAML
---
|
|
profiles::vault::server::members_role: roles::infra::storage::vault
|
|
profiles::vault::server::members_lookup: true
|
|
profiles::vault::server::data_dir: /data/vault
|
|
profiles::vault::server::plugin_dir: /opt/openbao-plugins
|
|
profiles::vault::server::manage_storage_dir: true
|
|
profiles::vault::server::tls_disable: false
|
|
profiles::vault::server::package_name: openbao
|
|
profiles::vault::server::package_ensure: 2.4.4
|
|
profiles::vault::server::disable_openbao: false
|
|
|
|
# additional altnames
|
|
profiles::pki::vault::alt_names:
|
|
- vault.main.unkin.net
|
|
- vault.service.consul
|
|
- vault.service.consul
|
|
- vault
|
|
|
|
# manage a simple nginx reverse proxy
|
|
profiles::nginx::simpleproxy::nginx_vhost: 'vault.service.consul'
|
|
profiles::nginx::simpleproxy::nginx_aliases:
|
|
- vault.main.unkin.net
|
|
- vault
|
|
profiles::nginx::simpleproxy::proxy_scheme: 'http'
|
|
profiles::nginx::simpleproxy::proxy_host: '127.0.0.1'
|
|
profiles::nginx::simpleproxy::proxy_port: 8200
|
|
profiles::nginx::simpleproxy::proxy_path: '/'
|
|
|
|
profiles::packages::include:
|
|
# openbao-plugins (base bundle) left unpinned; it tracks the openbao package.
|
|
openbao-plugins: {}
|
|
# Secrets plugins pinned to the exact version whose binary matches the sha256
|
|
# registered in terraform-vault (config/plugins/*.yaml). Bump both in lockstep
|
|
# on upgrade, or OpenBao refuses to launch the plugin after a restart.
|
|
openbao-plugin-secrets-litellm:
|
|
ensure: '0.1.1'
|
|
openbao-plugin-secrets-gpg:
|
|
ensure: '0.1.0'
|
|
openbao-plugin-secrets-rancher:
|
|
ensure: '0.1.1'
|
|
openbao-plugin-secrets-gitea:
|
|
ensure: '0.1.0'
|
|
openbao-plugin-secrets-apptoken:
|
|
ensure: '0.1.0'
|
|
openbao-plugin-secrets-netbox:
|
|
ensure: '0.1.0'
|
|
openbao-plugin-secrets-ghp:
|
|
ensure: '0.1.0'
|
|
openbao-plugin-secrets-arrstack:
|
|
ensure: '0.1.0'
|