Temporarily remove ghp secret backend + roles (unblock apply) (#129)
ci/woodpecker/push/apply Pipeline was successful
ci/woodpecker/push/apply Pipeline was successful
## Why The `terraform-vault` master apply aborts with: ``` Error: no secret found at "kv/data/service/vault/au/syd1/secret_backend/ghp/config" from module.ghp_secret_backend["ghp"].data.vault_kv_secret_v2.config ``` The ghp secret backend reads its admin token from a KV path that has not been seeded yet, so the apply fails and blocks every other change — including the arrstack plugin registration (#125). This PR **removes only the ghp backend + role config YAMLs (empties the `for_each` map)**. With no config YAMLs, `var.ghp_secret_backend` / `var.ghp_secret_backend_role` are empty maps, so zero ghp backend/role instances are created, the unseeded `ghp/config` KV is never read, and the apply passes. The ghp module wiring, plugin registration, and policies all stay in place. This is part 1 of a remove -> grant write policy -> seed KV -> re-add sequence, and the YAMLs will be restored once the ghp config KV is seeded. ## Changes - Delete `config/ghp_secret_backend/ghp.yaml`. - Delete `config/ghp_secret_backend_role/ghp/agent.yaml`. Net diff vs `master` is exactly those two file deletions. All ghp wiring is unchanged (identical to master): the `module.ghp_secret_backend` / `module.ghp_secret_backend_role` instantiations, their variables, the `config.hcl` parsing blocks, the `terragrunt.hcl` inputs, the `vault-plugin-secrets-ghp` plugin registration, and the `ghp/admin` + `ghp/creds/agent` policies all remain. Reviewed-on: #129 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #129.
This commit is contained in:
@@ -1,15 +0,0 @@
|
||||
# Mounts the ghp token secrets engine at "ghp" and writes its config.
|
||||
# The seeded ghp service token is sensitive and read from KV, not stored here:
|
||||
# kv/service/vault/au/syd1/secret_backend/ghp/config
|
||||
# -> key: admin_token (required) the shared ghpsvc_... service token
|
||||
#
|
||||
# admin_token is a static shared secret provisioned into KV by an operator. The
|
||||
# SAME token value must also be present in the running ghp deployment's accepted
|
||||
# service tokens (GHP_AUTH_SERVICE_TOKENS) so ghp ACCEPTS what this engine
|
||||
# PRESENTS. ghp has no rotate endpoint, so the engine never rotates it in place;
|
||||
# the mount uses ignore_changes=[admin_token], making the KV seed create-only
|
||||
# (re-reading a stale KV value never re-pushes it to a live mount).
|
||||
description: "ghp ephemeral scoped agent token engine"
|
||||
base_url: "https://ghp.unkin.net"
|
||||
tls_skip_verify: false
|
||||
request_timeout_seconds: 30
|
||||
@@ -1,15 +0,0 @@
|
||||
# Role minting ephemeral, scoped ghp agent tokens. Reading ghp/creds/agent mints
|
||||
# a lease-bound token deleted from ghp on revoke/expiry. token_type "agent" binds
|
||||
# the minted token to a ghp App installation, so installation_id is REQUIRED.
|
||||
#
|
||||
# installation_id below is a PLACEHOLDER (0) and MUST be set to the real ghp App
|
||||
# installation id before this role can mint usable tokens. scopes are ghp
|
||||
# permission:level pairs; contents:read is the least-privilege default.
|
||||
---
|
||||
token_type: agent
|
||||
installation_id: 0 # PLACEHOLDER - set to the real ghp App installation id
|
||||
scopes:
|
||||
- contents:read
|
||||
session_prefix: vault
|
||||
ttl: 3600 # 1h
|
||||
max_ttl: 86400 # 24h
|
||||
Reference in New Issue
Block a user