# terraform-rancher Terraform configuration for managing Rancher (rancher.k8s.syd1.au.unkin.net) authentication via the [rancher2](https://registry.terraform.io/providers/rancher/rancher2) provider. Mirrors the `terraform-authentik` pattern. ## Managed Resources - **Keycloak(OIDC) auth config** — Authentik OIDC login for Rancher. ## Configuration `config/keycloakoidc.yaml` defines the auth provider. The OAuth client secret is read from Vault (kv-v2) — the same secret Authentik sets on its `rancher` provider — and is never committed. `access_mode: unrestricted` lets any authenticated Authentik user log in; Rancher roles are granted to users/groups separately. This avoids locking the admin out when the provider is first enabled. ## Usage ```sh make plan # init + plan make apply # init + plan + apply make format # fmt tofu + terragrunt hcl ``` ### Authentication The rancher2 provider needs a Rancher admin API token, read from Vault at `kv/service/terraform/rancher` (field `token`). > **Note:** Rancher API tokens have a **90-day maximum** lifetime, so the static > token must be rotated. This is intended to move to a dedicated Vault Rancher > secrets engine that mints short-lived tokens on demand; when that lands, update > the Makefile `vault_env` helper to `vault read` from that engine. Set `VAULT_ROLEID` for local AppRole auth, or `VAULT_AUTH_METHOD=kubernetes` for CI (Woodpecker).