78ba0011f9
Configure the arrstack Vault secrets engine (backend config + roles) from terraform-vault, matching the schema declared in terraform-vault #127. - Add terraform-plugin-framework provider (local name arrstack) authenticating to Vault/OpenBao via address + token (VAULT_ADDR/VAULT_TOKEN fallback). - Add arrstack_secret_backend resource: mounts the engine and writes <mount>/config. - Add arrstack_secret_backend_role resource: manages <mount>/roles/<name>. - Add Vault client, conversions, unit tests, Makefile, woodpecker CI + tag release to artifactapi terraform-unkin, examples, and README.
42 lines
988 B
Terraform
42 lines
988 B
Terraform
terraform {
|
|
required_providers {
|
|
arrstack = {
|
|
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/vault-secrets-arrstack"
|
|
version = "0.1.0"
|
|
}
|
|
}
|
|
}
|
|
|
|
provider "arrstack" {
|
|
# address defaults to $VAULT_ADDR, token to $VAULT_TOKEN
|
|
}
|
|
|
|
variable "arrproxy_admin_token" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
resource "arrstack_secret_backend" "arrstack" {
|
|
path = "arrstack"
|
|
base_url = "https://arrstack.unkin.net"
|
|
admin_token = var.arrproxy_admin_token
|
|
}
|
|
|
|
# Role that mints an arrproxy API key scoped to all three arr apps.
|
|
resource "arrstack_secret_backend_role" "all" {
|
|
backend = arrstack_secret_backend.arrstack.path
|
|
name = "all"
|
|
apps = ["sonarr", "radarr", "prowlarr"]
|
|
ttl = 60
|
|
max_ttl = 86400
|
|
}
|
|
|
|
# Role scoped to Prowlarr only.
|
|
resource "arrstack_secret_backend_role" "prowlarr" {
|
|
backend = arrstack_secret_backend.arrstack.path
|
|
name = "prowlarr"
|
|
apps = ["prowlarr"]
|
|
ttl = 60
|
|
max_ttl = 86400
|
|
}
|