594635ba79
dnf install reads metadata for every enabled repo and downloads the vendored vault RPM on every pipeline run. Fetch the pinned upstream zip from the artifactapi hashicorp-releases remote instead, matching terraform-vault and terraform-artifactapi. - Replace dnf install vault with a pinned curl of the vault zip from the artifactapi hashicorp-releases remote, extracted to /usr/local/bin.
25 lines
812 B
YAML
25 lines
812 B
YAML
when:
|
|
- event: push
|
|
branch: main
|
|
|
|
steps:
|
|
- name: apply
|
|
image: git.unkin.net/unkin/almalinux9-opentofu:20260606
|
|
environment:
|
|
VAULT_AUTH_METHOD: kubernetes
|
|
VAULT_VERSION: "1.20.0"
|
|
commands:
|
|
- curl -fsSL -o /tmp/vault.zip "https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/hashicorp-releases/vault/$${VAULT_VERSION}/vault_$${VAULT_VERSION}_linux_amd64.zip" && python3 -m zipfile -e /tmp/vault.zip /tmp/ && install -m0755 /tmp/vault /usr/local/bin/vault && rm -f /tmp/vault.zip /tmp/vault /tmp/LICENSE.txt
|
|
- make plan
|
|
- make apply
|
|
backend_options:
|
|
kubernetes:
|
|
serviceAccountName: terraform-radarr
|
|
resources:
|
|
requests:
|
|
memory: 512Mi
|
|
cpu: 1
|
|
limits:
|
|
memory: 2Gi
|
|
cpu: 2
|