Engine plugin v0.2.0 added a `methods` field to roles, pinning a minted
arrproxy key to a set of HTTP methods so a read-only integration can be
handed a key that cannot write. The provider had no way to express it.
- Add an optional `methods` set attribute to arrstack_secret_backend_role,
validated at plan time against GET/HEAD/POST/PUT/PATCH/DELETE/OPTIONS.
- Always write `methods`, since the engine only clears a scope when the key
is present; an unrestricted role reads back as null rather than an empty
set so an omitted config value does not drift.
- Document the attribute in the README and examples, and cover the write
mapping, read-back, and validation in tests.
The arrstack engine returns `apps` alphabetically sorted regardless of the order they were written in, so modelling it as an ordered List makes any config whose order differs fail apply with "Provider produced inconsistent result after apply" and produce perpetual re-diffs. `apps` is semantically a set of app names, so it is now modelled as one.
- Changes the `apps` attribute on `arrstack_secret_backend_role` from `types.List`/`schema.ListAttribute` to `types.Set`/`schema.SetAttribute`
- Reads engine responses back via `types.SetValueFrom`
- Updates unit tests for the set type and adds an order-insensitivity test proving a sorted engine response equals a differently-ordered config value
- No other resources or data sources use the List-of-apps pattern
Reviewed-on: #2
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
Configure the arrstack Vault secrets engine (backend config + roles) from
terraform-vault, matching the schema declared in terraform-vault #127.
- Add terraform-plugin-framework provider (local name arrstack) authenticating
to Vault/OpenBao via address + token (VAULT_ADDR/VAULT_TOKEN fallback).
- Add arrstack_secret_backend resource: mounts the engine and writes <mount>/config.
- Add arrstack_secret_backend_role resource: manages <mount>/roles/<name>.
- Add Vault client, conversions, unit tests, Makefile, woodpecker CI + tag
release to artifactapi terraform-unkin, examples, and README.