ci: fetch vault from artifactapi instead of dnf install
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful

dnf install reads metadata for every enabled repo and downloads the
vendored vault RPM on every pipeline run. Fetch the pinned upstream zip
from the artifactapi hashicorp-releases remote instead, matching
terraform-vault and terraform-artifactapi.

- Replace dnf install vault with a pinned curl of the vault zip from the
  artifactapi hashicorp-releases remote, extracted to /usr/local/bin.
This commit is contained in:
2026-08-23 22:37:47 +10:00
parent 3d0b2069cc
commit b72fb609f7
2 changed files with 4 additions and 2 deletions
+2 -1
View File
@@ -7,8 +7,9 @@ steps:
image: git.unkin.net/unkin/almalinux9-opentofu:20260606 image: git.unkin.net/unkin/almalinux9-opentofu:20260606
environment: environment:
VAULT_AUTH_METHOD: kubernetes VAULT_AUTH_METHOD: kubernetes
VAULT_VERSION: "1.20.0"
commands: commands:
- dnf install vault -y - curl -fsSL -o /tmp/vault.zip "https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/hashicorp-releases/vault/$${VAULT_VERSION}/vault_$${VAULT_VERSION}_linux_amd64.zip" && python3 -m zipfile -e /tmp/vault.zip /tmp/ && install -m0755 /tmp/vault /usr/local/bin/vault && rm -f /tmp/vault.zip /tmp/vault /tmp/LICENSE.txt
- make plan - make plan
- make apply - make apply
backend_options: backend_options:
+2 -1
View File
@@ -6,8 +6,9 @@ steps:
image: git.unkin.net/unkin/almalinux9-opentofu:20260606 image: git.unkin.net/unkin/almalinux9-opentofu:20260606
environment: environment:
VAULT_AUTH_METHOD: kubernetes VAULT_AUTH_METHOD: kubernetes
VAULT_VERSION: "1.20.0"
commands: commands:
- dnf install vault -y - curl -fsSL -o /tmp/vault.zip "https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/hashicorp-releases/vault/$${VAULT_VERSION}/vault_$${VAULT_VERSION}_linux_amd64.zip" && python3 -m zipfile -e /tmp/vault.zip /tmp/ && install -m0755 /tmp/vault /usr/local/bin/vault && rm -f /tmp/vault.zip /tmp/vault /tmp/LICENSE.txt
- make plan - make plan
backend_options: backend_options:
kubernetes: kubernetes: