The provider api_url was hardcoded to the derived environment URL, leaving CI
no way to point a plan at a different endpoint. The rancher2 constraint of
>= 5.0.0 also permitted nine majors of drift against the 14.1.1 the lockfile
resolves.
- Add a generated variable "rancher_url" defaulting to the same
https://${path_relative_to_include()} expression; the provider now reads
var.rancher_url, so TF_VAR_rancher_url overrides without changing defaults.
- Pin rancher/rancher2 to ~> 14.0 in modules/rancher/versions.tf.
dnf install reads metadata for every enabled repo and downloads the
vendored vault RPM on every pipeline run. Fetch the pinned upstream zip
from the artifactapi hashicorp-releases remote instead, matching
terraform-vault and terraform-artifactapi.
- Replace dnf install vault with a pinned curl of the vault zip from the
artifactapi hashicorp-releases remote, extracted to /usr/local/bin.
PR plan pipelines were failing with "Error acquiring the state lock"
when they collided with a concurrent apply (or another plan) holding
the lock on the same Consul-backed state.
- plan: pass -lock=false to terragrunt plan; apply keeps locking
Rancher's server-side OIDC discovery call to the Authentik issuer
(https://identity.unkin.net) fails with x509 "certificate signed by
unknown authority" because Rancher does not trust the internal unkin.net
PKI. The keycloak_oidc auth config never set a CA certificate.
- Read the internal PKI ca_chain (intermediate + root) from Vault via a
vault_generic_secret data source (pki_int/cert/ca_chain).
- Set certificate on rancher2_auth_config_keycloak_oidc, defaulting to the
Vault-sourced chain so trust cannot go stale on rotation; add an optional
keycloakoidc.certificate override for an explicit value.
Issuer, client, scopes and role bindings are unchanged.
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
rancher2_global_role_binding.name must be a lowercase RFC 1123 label, but the
akP-* group keys are mixed-case, so apply failed with InvalidFormat 422.
Lowercase the name; keep the group principal id in original case to match the
Authentik group.
Consume the two-tier Authentik RBAC (terraform-authentik): read the hierarchical
`ak_groups` claim and grant Rancher global roles to the akP-rancher permission
groups. Members of akR-global-admin/akR-standard-user inherit these.
- keycloakoidc: scopes += ak_groups; groups_field = ak_groups
- global_role_bindings: akP-rancher-admin -> admin, akP-rancher-user -> user
(group principal keycloakoidc_group://<name>)
Manages Rancher's Keycloak(OIDC) auth provider via the rancher2 provider,
pointed at Authentik. Mirrors the terraform-authentik layout (terragrunt +
Vault-sourced secrets + Woodpecker plan/apply/pre-commit pipelines).
- modules/rancher: rancher2_auth_config_keycloak_oidc, client_secret read from
Vault (kv/kubernetes/namespace/cattle-system/default/oauth-credentials);
access_mode unrestricted to avoid admin lockout on enable.
- config/keycloakoidc.yaml: issuer/auth_endpoint at identity.unkin.net,
client_id rancher, /verify-auth redirect, openid/profile/email scopes.
- environments/rancher.k8s.syd1.au.unkin.net: consul state at
infra/terraform/rancher/, rancher2 provider api_url from the env name.
- rancher2 admin token read from kv/service/terraform/rancher (Makefile);
to migrate to a dedicated Vault Rancher secrets engine (90-day token cap).
Validated with `tofu validate` (config valid against the rancher2 provider).
A live `plan` needs the Rancher admin API token seeded in Vault first.