Scaffold terraform-provider-vault-secrets-arrstack
Configure the arrstack Vault secrets engine (backend config + roles) from terraform-vault, matching the schema declared in terraform-vault #127. - Add terraform-plugin-framework provider (local name arrstack) authenticating to Vault/OpenBao via address + token (VAULT_ADDR/VAULT_TOKEN fallback). - Add arrstack_secret_backend resource: mounts the engine and writes <mount>/config. - Add arrstack_secret_backend_role resource: manages <mount>/roles/<name>. - Add Vault client, conversions, unit tests, Makefile, woodpecker CI + tag release to artifactapi terraform-unkin, examples, and README.
This commit is contained in:
@@ -0,0 +1,26 @@
|
||||
terraform {
|
||||
required_providers {
|
||||
arrstack = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/vault-secrets-arrstack"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
provider "arrstack" {
|
||||
# address / token fall back to VAULT_ADDR / VAULT_TOKEN.
|
||||
}
|
||||
|
||||
# Mount the arrstack secrets engine and seed it with the arrproxy admin token.
|
||||
resource "arrstack_secret_backend" "arrstack" {
|
||||
path = "arrstack"
|
||||
base_url = "https://arrstack.unkin.net"
|
||||
|
||||
admin_token = var.arrproxy_admin_token # e.g. sourced from vault_kv_secret_v2
|
||||
|
||||
request_timeout_seconds = 30
|
||||
}
|
||||
|
||||
variable "arrproxy_admin_token" {
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
@@ -0,0 +1,11 @@
|
||||
# A role that mints short-lived arrproxy API keys scoped to a subset of the arr
|
||||
# apps. Reading arrstack/creds/<role> returns a lease-bound key that the engine
|
||||
# revokes when the lease ends.
|
||||
resource "arrstack_secret_backend_role" "sonarr" {
|
||||
backend = arrstack_secret_backend.arrstack.path
|
||||
name = "sonarr"
|
||||
apps = ["sonarr"]
|
||||
|
||||
ttl = 60 # 1m
|
||||
max_ttl = 86400 # 24h
|
||||
}
|
||||
Reference in New Issue
Block a user