unkin-agent 11260a81a4
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci: fetch vault from artifactapi instead of dnf install
dnf install reads metadata for every enabled repo and downloads the
vendored vault RPM on every pipeline run. Fetch the pinned upstream zip
from the artifactapi hashicorp-releases remote instead, matching
terraform-vault and terraform-artifactapi.

- Replace dnf install vault with a pinned curl of the vault zip from the
  artifactapi hashicorp-releases remote, extracted to /usr/local/bin.
2026-08-23 22:38:04 +10:00

terraform-rancher

Terraform configuration for managing Rancher (rancher.k8s.syd1.au.unkin.net) authentication via the rancher2 provider. Mirrors the terraform-authentik pattern.

Managed Resources

  • Keycloak(OIDC) auth config — Authentik OIDC login for Rancher.

Configuration

config/keycloakoidc.yaml defines the auth provider. The OAuth client secret is read from Vault (kv-v2) — the same secret Authentik sets on its rancher provider — and is never committed.

access_mode: unrestricted lets any authenticated Authentik user log in; Rancher roles are granted to users/groups separately. This avoids locking the admin out when the provider is first enabled.

Usage

make plan    # init + plan
make apply   # init + plan + apply
make format  # fmt tofu + terragrunt hcl

Authentication

The rancher2 provider needs a Rancher admin API token, read from Vault at kv/service/terraform/rancher (field token).

Note: Rancher API tokens have a 90-day maximum lifetime, so the static token must be rotated. This is intended to move to a dedicated Vault Rancher secrets engine that mints short-lived tokens on demand; when that lands, update the Makefile vault_env helper to vault read from that engine.

Set VAULT_ROLEID for local AppRole auth, or VAULT_AUTH_METHOD=kubernetes for CI (Woodpecker).

S
Description
Terraform configuration for managing Rancher (auth, roles) via the rancher2 provider
Readme 77 KiB
Languages
HCL 91%
Makefile 9%