Files
puppet-prod/site/profiles/manifests
unkin-agent 9db9afae8d
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/puppet-validate Pipeline was successful
ci/woodpecker/pr/ruby-check Pipeline was successful
Let certmanager and sshsignhost authenticate to Vault by kubernetes auth
Both helpers are run server-side by generate() during catalog compilation and
only speak AppRole, whose token_bound_cidrs pin them to the six legacy VM
masters, so the autoscaled k8s compilers cannot obtain a token and any compile
needing a cert or a signed host key fails there.

- Add a kubernetes login branch that reads the service account JWT and posts it
  to auth/<k8s_mount>/login, selected by an auth_method config key
- Add auth_method, k8s_mount, k8s_role and jwt_path class parameters, defaulting
  to approle so the VM masters render and behave as before
- Render role_id and approle_path only for the approle case
- Report a missing JWT, a rejected login or an unknown auth_method on stderr
  instead of falling back or raising
- Point sshsignhost at the sshca mount and signhost role that Vault actually has

Needs terraform-vault #152, already applied.
2026-09-13 23:06:32 +10:00
..
2024-04-13 22:34:28 +10:00
2025-07-06 11:27:35 +10:00
2023-11-17 22:17:24 +11:00
2025-06-29 13:36:16 +10:00
2026-01-03 21:51:47 +11:00
2024-07-01 22:54:22 +10:00
2025-06-15 17:43:19 +10:00
2024-03-16 16:43:12 +11:00
2024-07-08 22:33:11 +10:00
2023-11-17 22:25:43 +11:00
2024-08-06 22:33:32 +10:00
2025-04-24 16:51:31 +10:00
2025-04-24 23:03:01 +10:00
2024-07-28 01:51:41 +10:00