646fa0f840
Add a Terraform provider that manages the Gitea token secrets engine (vault-plugin-secrets-gitea) on Vault/OpenBao, so terraform-vault can drive the engine's mount, config, and roles declaratively. - add the provider (source git.unkin.net/unkin/giteavaultsecret, prefix gitea_) - add gitea_secret_backend (mount + config with seeded admin credentials) - add gitea_secret_backend_role (username, scopes list, ttls, token_name_prefix) - add the Vault API client plumbing, conversions, and unit tests - add examples, a real terraform+Vault+mock-Gitea e2e, and Woodpecker pipelines releasing the provider zip to the artifactapi terraform registry Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
13 lines
432 B
Terraform
13 lines
432 B
Terraform
# A role that mints short-lived tokens for the "teabot" bot user, scoped to
|
|
# repositories and issues. Reading gitea/creds/teabot returns a lease-bound token
|
|
# that is deleted from Gitea on revoke.
|
|
resource "gitea_secret_backend_role" "teabot" {
|
|
backend = gitea_secret_backend.gitea.path
|
|
name = "teabot"
|
|
username = "teabot"
|
|
scopes = ["read:repository", "write:issue"]
|
|
|
|
ttl = 3600 # 1h
|
|
max_ttl = 28800 # 8h
|
|
}
|