986aecd28f
Model the provider on terraform-provider-giteavaultsecret, adjusting the schemas to the ghp engine (vault-plugin-secrets-ghp) so its mount, config, and roles can be managed declaratively. - Add provider (local name ghpvaultsecret, source git.unkin.net/unkin/ghpvaultsecret) with VAULT_ADDR/VAULT_TOKEN fallback. - Add ghpvaultsecret_secret_backend: mounts the engine and writes config (base_url, write-only admin_token, write-only ca_cert, tls_skip_verify, request_timeout_seconds); read never returns the sensitive fields. - Add ghpvaultsecret_secret_role: token_type, installation_id, app_record_id, repositories, scopes, session_prefix, ttl, max_ttl; validate that agent roles set installation_id. - Add unit tests for the value conversions and the role/backend field mapping. - Mirror the woodpecker pre-commit/build/test (PR) and tag release (package + PUT zip to the artifactapi terraform registry) pipelines, Makefile version bump/package targets, examples, README, and a Docker e2e harness.
66 lines
2.1 KiB
Makefile
66 lines
2.1 KiB
Makefile
.PHONY: build install test lint fmt clean tidy package e2e patch minor major check-go
|
|
|
|
BINARY := terraform-provider-ghpvaultsecret
|
|
VERSION ?= $(shell git describe --tags --always --dirty 2>/dev/null || echo "0.0.0-dev")
|
|
OS_ARCH := linux_amd64
|
|
INSTALL_VERSION := $(shell echo $(VERSION) | sed 's/^v//')
|
|
INSTALL_DIR := ~/.terraform.d/plugins/git.unkin.net/unkin/ghpvaultsecret/$(INSTALL_VERSION)/$(OS_ARCH)
|
|
ZIP := $(BINARY)_$(INSTALL_VERSION)_$(OS_ARCH).zip
|
|
|
|
GO_VERSION_REQUIRED := 1.25
|
|
GO_VERSION_ACTUAL := $(shell go version | sed 's/go version go\([0-9]*\.[0-9]*\).*/\1/')
|
|
|
|
check-go:
|
|
@if [ "$$(printf '%s\n%s' "$(GO_VERSION_REQUIRED)" "$(GO_VERSION_ACTUAL)" | sort -V | head -1)" != "$(GO_VERSION_REQUIRED)" ]; then \
|
|
echo "ERROR: Go >= $(GO_VERSION_REQUIRED) required, found $(GO_VERSION_ACTUAL)"; exit 1; \
|
|
fi
|
|
|
|
build: check-go tidy
|
|
go build -ldflags="-s -w -X main.version=$(VERSION)" -o $(BINARY)
|
|
|
|
install: build
|
|
mkdir -p $(INSTALL_DIR)
|
|
cp $(BINARY) $(INSTALL_DIR)/
|
|
|
|
test: check-go
|
|
go test -race -count=1 ./...
|
|
|
|
lint: check-go
|
|
go vet ./...
|
|
|
|
fmt: check-go
|
|
gofmt -w .
|
|
|
|
package: build
|
|
cp $(BINARY) $(BINARY)_v$(INSTALL_VERSION)
|
|
python3 -c "import zipfile,sys; z=zipfile.ZipFile(sys.argv[1],'w',zipfile.ZIP_DEFLATED); z.write(sys.argv[2]); z.close()" $(ZIP) $(BINARY)_v$(INSTALL_VERSION)
|
|
rm $(BINARY)_v$(INSTALL_VERSION)
|
|
|
|
# End-to-end: boots Vault + mock ghp + the plugin and applies real terraform.
|
|
e2e:
|
|
./scripts/e2e.sh
|
|
|
|
clean:
|
|
rm -f $(BINARY) *.zip
|
|
|
|
tidy:
|
|
go mod tidy
|
|
|
|
_LATEST := $(shell git tag --sort=-v:refname | grep -E '^v[0-9]+\.[0-9]+\.[0-9]+$$' | head -1)
|
|
_BASE := $(if $(_LATEST),$(_LATEST),v0.0.0)
|
|
_MAJ := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f1)
|
|
_MIN := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f2)
|
|
_PAT := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f3)
|
|
|
|
patch:
|
|
@NEW=v$(_MAJ).$(_MIN).$(shell expr $(_PAT) + 1); \
|
|
git tag $$NEW && echo "Tagged $$NEW" && git push origin $$NEW
|
|
|
|
minor:
|
|
@NEW=v$(_MAJ).$(shell expr $(_MIN) + 1).0; \
|
|
git tag $$NEW && echo "Tagged $$NEW" && git push origin $$NEW
|
|
|
|
major:
|
|
@NEW=v$(shell expr $(_MAJ) + 1).0.0; \
|
|
git tag $$NEW && echo "Tagged $$NEW" && git push origin $$NEW
|