From 2525bae1d76a7e7e5ca8698d4e9ec1033b31c826 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Wed, 19 Aug 2026 22:51:55 +1000 Subject: [PATCH] Temporarily remove ghp secret backend + roles (unblock apply) (#129) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ## Why The `terraform-vault` master apply aborts with: ``` Error: no secret found at "kv/data/service/vault/au/syd1/secret_backend/ghp/config" from module.ghp_secret_backend["ghp"].data.vault_kv_secret_v2.config ``` The ghp secret backend reads its admin token from a KV path that has not been seeded yet, so the apply fails and blocks every other change — including the arrstack plugin registration (#125). This PR **removes only the ghp backend + role config YAMLs (empties the `for_each` map)**. With no config YAMLs, `var.ghp_secret_backend` / `var.ghp_secret_backend_role` are empty maps, so zero ghp backend/role instances are created, the unseeded `ghp/config` KV is never read, and the apply passes. The ghp module wiring, plugin registration, and policies all stay in place. This is part 1 of a remove -> grant write policy -> seed KV -> re-add sequence, and the YAMLs will be restored once the ghp config KV is seeded. ## Changes - Delete `config/ghp_secret_backend/ghp.yaml`. - Delete `config/ghp_secret_backend_role/ghp/agent.yaml`. Net diff vs `master` is exactly those two file deletions. All ghp wiring is unchanged (identical to master): the `module.ghp_secret_backend` / `module.ghp_secret_backend_role` instantiations, their variables, the `config.hcl` parsing blocks, the `terragrunt.hcl` inputs, the `vault-plugin-secrets-ghp` plugin registration, and the `ghp/admin` + `ghp/creds/agent` policies all remain. Reviewed-on: https://git.unkin.net/unkin/terraform-vault/pulls/129 Co-authored-by: unkin-agent Co-committed-by: unkin-agent --- config/ghp_secret_backend/ghp.yaml | 15 --------------- config/ghp_secret_backend_role/ghp/agent.yaml | 15 --------------- 2 files changed, 30 deletions(-) delete mode 100644 config/ghp_secret_backend/ghp.yaml delete mode 100644 config/ghp_secret_backend_role/ghp/agent.yaml diff --git a/config/ghp_secret_backend/ghp.yaml b/config/ghp_secret_backend/ghp.yaml deleted file mode 100644 index ecff20b..0000000 --- a/config/ghp_secret_backend/ghp.yaml +++ /dev/null @@ -1,15 +0,0 @@ -# Mounts the ghp token secrets engine at "ghp" and writes its config. -# The seeded ghp service token is sensitive and read from KV, not stored here: -# kv/service/vault/au/syd1/secret_backend/ghp/config -# -> key: admin_token (required) the shared ghpsvc_... service token -# -# admin_token is a static shared secret provisioned into KV by an operator. The -# SAME token value must also be present in the running ghp deployment's accepted -# service tokens (GHP_AUTH_SERVICE_TOKENS) so ghp ACCEPTS what this engine -# PRESENTS. ghp has no rotate endpoint, so the engine never rotates it in place; -# the mount uses ignore_changes=[admin_token], making the KV seed create-only -# (re-reading a stale KV value never re-pushes it to a live mount). -description: "ghp ephemeral scoped agent token engine" -base_url: "https://ghp.unkin.net" -tls_skip_verify: false -request_timeout_seconds: 30 diff --git a/config/ghp_secret_backend_role/ghp/agent.yaml b/config/ghp_secret_backend_role/ghp/agent.yaml deleted file mode 100644 index b5653c7..0000000 --- a/config/ghp_secret_backend_role/ghp/agent.yaml +++ /dev/null @@ -1,15 +0,0 @@ -# Role minting ephemeral, scoped ghp agent tokens. Reading ghp/creds/agent mints -# a lease-bound token deleted from ghp on revoke/expiry. token_type "agent" binds -# the minted token to a ghp App installation, so installation_id is REQUIRED. -# -# installation_id below is a PLACEHOLDER (0) and MUST be set to the real ghp App -# installation id before this role can mint usable tokens. scopes are ghp -# permission:level pairs; contents:read is the least-privilege default. ---- -token_type: agent -installation_id: 0 # PLACEHOLDER - set to the real ghp App installation id -scopes: - - contents:read -session_prefix: vault -ttl: 3600 # 1h -max_ttl: 86400 # 24h