From 31424ea6ffe0d7553e2e1e8b4aa3f387cbacce08 Mon Sep 17 00:00:00 2001 From: Ben Vincent Date: Sat, 25 Jul 2026 09:47:34 +1000 Subject: [PATCH] ci: fetch vault from artifactapi instead of dnf install (#99) ## Why CI installs vault by shelling out to `dnf install vault -y`. That reads metadata for every enabled repo (appstream/baseos/crb/epel/ha) and downloads the 169MB vendored vault RPM from the `unkin` repo on **every** plan/apply run (~39s per job measured in `almalinux9-opentofu:20260606`). ## Change - Replace `dnf install vault -y` with a pinned `curl` of the upstream vault zip from the artifactapi `hashicorp-releases` remote proxy, extracted with the image's `python3` (`python3 -m zipfile`) to `/usr/local/bin/vault`. - Pin the version via a new `VAULT_VERSION` env var (`1.20.0`); bump the var to upgrade. ## Speedup Measured in `git.unkin.net/unkin/almalinux9-opentofu:20260606`: | approach | time | |---|---| | `dnf install vault -y` (current) | ~39s | | `dnf --disablerepo='*' --enablerepo=unkin` (still pulls 169MB RPM) | ~9s | | curl zip from artifactapi + python extract (this PR) | ~6.6s | ~32s saved per plan/apply job. The zip is cached by artifactapi after first fetch (warm ~3s). ## Caveats - Assumes the `almalinux9-opentofu` image ships `curl` + `python3` (both present in `:20260606`). - Relies on the existing artifactapi `hashicorp-releases` generic remote whose patterns already allow `vault/.*vault_.*_linux_amd64.zip`. --------- Co-authored-by: benvin Reviewed-on: https://git.unkin.net/unkin/terraform-vault/pulls/99 Co-authored-by: Ben Vincent Co-committed-by: Ben Vincent --- .woodpecker/apply.yaml | 3 ++- .woodpecker/plan.yaml | 3 ++- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/.woodpecker/apply.yaml b/.woodpecker/apply.yaml index 49a9322..6eb54b4 100644 --- a/.woodpecker/apply.yaml +++ b/.woodpecker/apply.yaml @@ -7,8 +7,9 @@ steps: image: git.unkin.net/unkin/almalinux9-opentofu:20260606 environment: VAULT_AUTH_METHOD: kubernetes + VAULT_VERSION: "1.20.0" commands: - - dnf install vault -y + - curl -fsSL -o /tmp/vault.zip "https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/hashicorp-releases/vault/$${VAULT_VERSION}/vault_$${VAULT_VERSION}_linux_amd64.zip" && python3 -m zipfile -e /tmp/vault.zip /tmp/ && install -m0755 /tmp/vault /usr/local/bin/vault && rm -f /tmp/vault.zip /tmp/vault /tmp/LICENSE.txt - make plan - make apply backend_options: diff --git a/.woodpecker/plan.yaml b/.woodpecker/plan.yaml index 3800f90..6f7191e 100644 --- a/.woodpecker/plan.yaml +++ b/.woodpecker/plan.yaml @@ -6,8 +6,9 @@ steps: image: git.unkin.net/unkin/almalinux9-opentofu:20260606 environment: VAULT_AUTH_METHOD: kubernetes + VAULT_VERSION: "1.20.0" commands: - - dnf install vault -y + - curl -fsSL -o /tmp/vault.zip "https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/hashicorp-releases/vault/$${VAULT_VERSION}/vault_$${VAULT_VERSION}_linux_amd64.zip" && python3 -m zipfile -e /tmp/vault.zip /tmp/ && install -m0755 /tmp/vault /usr/local/bin/vault && rm -f /tmp/vault.zip /tmp/vault /tmp/LICENSE.txt - make plan backend_options: kubernetes: