Restore ghp secret backend + roles (config now seeded)
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful

Reverts the temporary removal in #129. The ghp config KV path
kv/data/service/vault/au/syd1/secret_backend/ghp/config (key admin_token)
is now seeded, and the ghp service secret carries the matching service_token,
so data.vault_kv_secret_v2.config resolves and the backend + role can be
created.

Restore config/ghp_secret_backend/ghp.yaml.
Restore config/ghp_secret_backend_role/ghp/agent.yaml.

Net diff vs master is exactly the re-addition of those two files (mirror-inverse
of #129). Final step of the remove -> grant -> seed -> add-back sequence.
This commit is contained in:
2026-08-19 23:34:15 +10:00
parent d1cb790de8
commit 31d7a6a427
2 changed files with 30 additions and 0 deletions
+15
View File
@@ -0,0 +1,15 @@
# Mounts the ghp token secrets engine at "ghp" and writes its config.
# The seeded ghp service token is sensitive and read from KV, not stored here:
# kv/service/vault/au/syd1/secret_backend/ghp/config
# -> key: admin_token (required) the shared ghpsvc_... service token
#
# admin_token is a static shared secret provisioned into KV by an operator. The
# SAME token value must also be present in the running ghp deployment's accepted
# service tokens (GHP_AUTH_SERVICE_TOKENS) so ghp ACCEPTS what this engine
# PRESENTS. ghp has no rotate endpoint, so the engine never rotates it in place;
# the mount uses ignore_changes=[admin_token], making the KV seed create-only
# (re-reading a stale KV value never re-pushes it to a live mount).
description: "ghp ephemeral scoped agent token engine"
base_url: "https://ghp.unkin.net"
tls_skip_verify: false
request_timeout_seconds: 30
@@ -0,0 +1,15 @@
# Role minting ephemeral, scoped ghp agent tokens. Reading ghp/creds/agent mints
# a lease-bound token deleted from ghp on revoke/expiry. token_type "agent" binds
# the minted token to a ghp App installation, so installation_id is REQUIRED.
#
# installation_id below is a PLACEHOLDER (0) and MUST be set to the real ghp App
# installation id before this role can mint usable tokens. scopes are ghp
# permission:level pairs; contents:read is the least-privilege default.
---
token_type: agent
installation_id: 0 # PLACEHOLDER - set to the real ghp App installation id
scopes:
- contents:read
session_prefix: vault
ttl: 3600 # 1h
max_ttl: 86400 # 24h