a025819fcd
Why: - The netbox provider authenticated with a static netbox_token seeded by hand into KV; the vault-plugin-secrets-netbox engine mints a per-run ephemeral token that is lease-revoked when the run ends, removing the manual seed. How: - Read netbox/creds/terraform-infra via vault_generic_secret and pass the minted netbox_token to the netbox provider. - Keep kea_token from KV for now (follow-up: its own ephemeral-token engine). Depends on the netbox engine mount + netbox/creds/terraform-infra role/policy in terraform-vault being applied first.
32 lines
1018 B
Terraform
32 lines
1018 B
Terraform
provider "vault" {
|
|
address = var.vault_address
|
|
# The woodpecker_terraform_infra role cannot mint child tokens (auth/token/create
|
|
# is denied); use the login token directly.
|
|
skip_child_token = true
|
|
}
|
|
|
|
# NetBox API token: minted per run by the vault-plugin-secrets-netbox engine
|
|
# (netbox/creds/terraform-infra), lease-revoked when the run ends. This replaces
|
|
# the static netbox_token that was seeded into KV by hand.
|
|
data "vault_generic_secret" "netbox" {
|
|
path = "netbox/creds/terraform-infra"
|
|
}
|
|
|
|
# KeaAPI token still lives in the KV v2 secret (follow-up: give Kea its own
|
|
# ephemeral-token engine). The vault provider authenticates with the VAULT_TOKEN
|
|
# set by the Makefile.
|
|
data "vault_kv_secret_v2" "tokens" {
|
|
mount = "kv"
|
|
name = "service/terraform/infra"
|
|
}
|
|
|
|
provider "netbox" {
|
|
server_url = var.netbox_server_url
|
|
api_token = data.vault_generic_secret.netbox.data["netbox_token"]
|
|
}
|
|
|
|
provider "kea" {
|
|
endpoint = var.kea_endpoint
|
|
token = data.vault_kv_secret_v2.tokens.data["kea_token"]
|
|
}
|