646fa0f840
Add a Terraform provider that manages the Gitea token secrets engine (vault-plugin-secrets-gitea) on Vault/OpenBao, so terraform-vault can drive the engine's mount, config, and roles declaratively. - add the provider (source git.unkin.net/unkin/giteavaultsecret, prefix gitea_) - add gitea_secret_backend (mount + config with seeded admin credentials) - add gitea_secret_backend_role (username, scopes list, ttls, token_name_prefix) - add the Vault API client plumbing, conversions, and unit tests - add examples, a real terraform+Vault+mock-Gitea e2e, and Woodpecker pipelines releasing the provider zip to the artifactapi terraform registry Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
29 lines
649 B
Terraform
29 lines
649 B
Terraform
terraform {
|
|
required_providers {
|
|
gitea = {
|
|
source = "git.unkin.net/unkin/giteavaultsecret"
|
|
}
|
|
}
|
|
}
|
|
|
|
provider "gitea" {
|
|
# address / token fall back to VAULT_ADDR / VAULT_TOKEN.
|
|
}
|
|
|
|
# Mount the Gitea secrets engine and seed it with a site-admin credential.
|
|
resource "gitea_secret_backend" "gitea" {
|
|
path = "gitea"
|
|
gitea_url = "https://git.example.com"
|
|
ca_cert = file("${path.module}/gitea-ca.pem")
|
|
|
|
admin_username = "bot-admin"
|
|
admin_password = var.gitea_admin_password # e.g. sourced from vault_kv_secret
|
|
|
|
request_timeout_seconds = 30
|
|
}
|
|
|
|
variable "gitea_admin_password" {
|
|
type = string
|
|
sensitive = true
|
|
}
|