From 1fa590078701bf6b925a00b73f84b68360f6c958 Mon Sep 17 00:00:00 2001 From: Ben Vincent Date: Fri, 24 Jul 2026 23:18:56 +1000 Subject: [PATCH] Add terraform-enc Vault/Consul plumbing + encapi token grant (#98) The new **terragrunt-enc** repo manages all encapi ENC data (statuses, roles, node classifications) via Terraform/Terragrunt and needs its own Vault/Consul plumbing, mirroring terraform-git and terraform-incus. This supersedes the dual-write approach in terraform-incus PR #39; the equivalent terraform-incus grant (PR #97) is being closed, so the encapi-token grant is created fresh here for the new approle. Changes: - Add approle role `terraform_enc` and k8s auth role `woodpecker_terraform_enc` (bound to the `terraform-enc` ServiceAccount in the `woodpecker` namespace) for CI auth. - Add consul secret backend role `terraform-enc` plus its ACL rules granting `write` on `infra/terraform/enc/` (its terragrunt state prefix), and a policy letting both auth roles read `consul_root/au/syd1/creds/terraform-enc`. - Grant both auth roles read on `kv/data/kubernetes/namespace/encapi/default/environment` (the ENCAPI_WRITE_TOKEN) so `make apply` can write to encapi via the encapi provider. Reviewed-on: https://git.unkin.net/unkin/terraform-vault/pulls/98 Co-authored-by: Ben Vincent Co-committed-by: Ben Vincent --- .../auth_approle_role/approle/terraform_enc.yaml | 9 +++++++++ .../k8s/au/syd1/woodpecker_terraform_enc.yaml | 7 +++++++ .../consul_root/au/syd1/terraform-enc.yaml | 5 +++++ .../consul_root/au/syd1/creds/terraform-enc.yaml | 14 ++++++++++++++ .../service/terraform/enc-encapi-environment.yaml | 14 ++++++++++++++ .../consul_root/au/syd1/terraform-enc.hcl | 7 +++++++ 6 files changed, 56 insertions(+) create mode 100644 config/auth_approle_role/approle/terraform_enc.yaml create mode 100644 config/auth_kubernetes_role/k8s/au/syd1/woodpecker_terraform_enc.yaml create mode 100644 config/consul_secret_backend_role/consul_root/au/syd1/terraform-enc.yaml create mode 100644 policies/consul_root/au/syd1/creds/terraform-enc.yaml create mode 100644 policies/kv/service/terraform/enc-encapi-environment.yaml create mode 100644 resources/secret_backend/consul_root/au/syd1/terraform-enc.hcl diff --git a/config/auth_approle_role/approle/terraform_enc.yaml b/config/auth_approle_role/approle/terraform_enc.yaml new file mode 100644 index 0000000..cec109a --- /dev/null +++ b/config/auth_approle_role/approle/terraform_enc.yaml @@ -0,0 +1,9 @@ +token_ttl: 120 +token_max_ttl: 120 +bind_secret_id: false +token_bound_cidrs: + - "10.10.12.200/32" + - "198.18.25.102/32" + - "198.18.26.91/32" + - "198.18.27.40/32" +use_deterministic_role_id: true diff --git a/config/auth_kubernetes_role/k8s/au/syd1/woodpecker_terraform_enc.yaml b/config/auth_kubernetes_role/k8s/au/syd1/woodpecker_terraform_enc.yaml new file mode 100644 index 0000000..e433ccf --- /dev/null +++ b/config/auth_kubernetes_role/k8s/au/syd1/woodpecker_terraform_enc.yaml @@ -0,0 +1,7 @@ +bound_service_account_names: + - terraform-enc +bound_service_account_namespaces: + - woodpecker +token_ttl: 600 +token_max_ttl: 600 +audience: https://kubernetes.default.svc.cluster.local diff --git a/config/consul_secret_backend_role/consul_root/au/syd1/terraform-enc.yaml b/config/consul_secret_backend_role/consul_root/au/syd1/terraform-enc.yaml new file mode 100644 index 0000000..4b40640 --- /dev/null +++ b/config/consul_secret_backend_role/consul_root/au/syd1/terraform-enc.yaml @@ -0,0 +1,5 @@ +consul_roles: + - terraform-enc +ttl: 120 +max_ttl: 300 +datacenters: [] diff --git a/policies/consul_root/au/syd1/creds/terraform-enc.yaml b/policies/consul_root/au/syd1/creds/terraform-enc.yaml new file mode 100644 index 0000000..d03d91d --- /dev/null +++ b/policies/consul_root/au/syd1/creds/terraform-enc.yaml @@ -0,0 +1,14 @@ +# Allow the terragrunt-enc runner to generate credentials for the +# terraform-enc role in consul (used to lock/write its terragrunt state under +# infra/terraform/enc/ on the consul backend). +--- +rules: + - path: "consul_root/au/syd1/creds/terraform-enc" + capabilities: + - read + +auth: + approle: + - terraform_enc + k8s/au/syd1: + - woodpecker_terraform_enc diff --git a/policies/kv/service/terraform/enc-encapi-environment.yaml b/policies/kv/service/terraform/enc-encapi-environment.yaml new file mode 100644 index 0000000..7571698 --- /dev/null +++ b/policies/kv/service/terraform/enc-encapi-environment.yaml @@ -0,0 +1,14 @@ +# Allow the terragrunt-enc runner to read the encapi environment secret +# (ENCAPI_WRITE_TOKEN), so `make apply` can write ENC data (statuses, roles, +# nodes) to encapi via the encapi Terraform provider. +--- +rules: + - path: "kv/data/kubernetes/namespace/encapi/default/environment" + capabilities: + - read + +auth: + approle: + - terraform_enc + k8s/au/syd1: + - woodpecker_terraform_enc diff --git a/resources/secret_backend/consul_root/au/syd1/terraform-enc.hcl b/resources/secret_backend/consul_root/au/syd1/terraform-enc.hcl new file mode 100644 index 0000000..e0c6310 --- /dev/null +++ b/resources/secret_backend/consul_root/au/syd1/terraform-enc.hcl @@ -0,0 +1,7 @@ +key_prefix "infra/terraform/enc/" { + policy = "write" +} + +session_prefix "" { + policy = "write" +}