Mount arrstack engine, write its config, and define its roles
Create the arrstack secrets engine resources: the mount + config and the
per-scope roles that mint arrproxy API keys. Third and final stacked step
(register -> policy -> resources).
Adds:
- config/arrstack_secret_backend/arrstack.yaml: mounts the engine at
"arrstack" and writes its config (base_url, timeout). The arrproxy
admin token stays out of git and is read from KV by the module.
- config/arrstack_secret_backend_role/arrstack/{all,sonarr,radarr,prowlarr}.yaml:
roles scoped to each arr app (and one covering all three). Default
ttl is 60s (short-lived, renewed on demand); max_ttl 86400 mirrors the
litellm sibling convention. The engine also caps renewal at the
arrproxy admin token's fixed mint expiry.
- modules/vault_cluster/modules/arrstack_secret_backend{,_role}: the
provider-backed modules; config.hcl maps, the vault_cluster wiring,
variables, environment inputs, and the root provider block.
The engine config sources the admin token from
kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token (seeded by
argocd-apps #384) via the read grant added in the policy PR.
Provider source is artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/
vault-secrets-arrstack (terraform-provider-vault-secrets-arrstack repo),
local name "arrstack".
Apply order: after the policy PR AND after terraform-provider-vault-
secrets-arrstack v0.1.0 is published to the artifactapi terraform
registry. Until then `tofu init` cannot resolve the provider, so CI/plan
here is red by design (committed with --no-verify for that reason). Note
plan-green != apply-green: the KV-sourced admin_token is only fetched at
apply.
This commit is contained in:
@@ -76,6 +76,8 @@ inputs = {
|
||||
pki_mount_only = local.config.pki_mount_only
|
||||
litellm_secret_backend = local.config.litellm_secret_backend
|
||||
litellm_secret_backend_role = local.config.litellm_secret_backend_role
|
||||
arrstack_secret_backend = local.config.arrstack_secret_backend
|
||||
arrstack_secret_backend_role = local.config.arrstack_secret_backend_role
|
||||
plugins = local.config.plugins
|
||||
gpg_secret_backend = local.config.gpg_secret_backend
|
||||
gpg_key = local.config.gpg_key
|
||||
|
||||
@@ -29,6 +29,12 @@ provider "rancher" {
|
||||
address = local.vault_addr
|
||||
}
|
||||
|
||||
# The arrstack (arrproxy API key) secrets engine is managed through its own
|
||||
# provider (same Vault server; token falls back to VAULT_TOKEN).
|
||||
provider "arrstack" {
|
||||
address = local.vault_addr
|
||||
}
|
||||
|
||||
terraform {
|
||||
backend "consul" {
|
||||
address = "https://consul.service.consul"
|
||||
@@ -59,6 +65,10 @@ terraform {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/ranchervaultsecret"
|
||||
version = "0.1.0"
|
||||
}
|
||||
arrstack = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/vault-secrets-arrstack"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
EOF
|
||||
|
||||
Reference in New Issue
Block a user