Mount the rancher secrets engine + seed a service account + roles (#93)
ci/woodpecker/push/apply Pipeline was successful
ci/woodpecker/push/apply Pipeline was successful
## Why Deploy the new Rancher token secrets engine into the cluster (the last of the 4 wiring PRs), mirroring the litellm/gpg pattern. Users can then `vault read rancher/creds/<role>` for short-lived, cluster-scoped Rancher tokens, backed by a seeded admin token the engine auto-rotates before Rancher's 90-day cap. ## Changes - Add `rancher_secret_backend` module — mount + config via the ranchervaultsecret provider (rancher_url `https://rancher.k8s.syd1.au.unkin.net`). - Add `rancher_secret_backend_service_account` module — seeds an auto-rotated token (90d TTL / 45d rotation); the seed token is read from KV, not git. - Add `rancher_secret_backend_role` module + a `ci` role (1h/8h, cluster+TTL scoped). - Wire `config.hcl` discovery, module variables, `main.tf` blocks, terragrunt inputs, and the `rancher` provider in `root.hcl`. - Config: `config/rancher_secret_backend/rancher.yaml`, `.../service_account/rancher/admin.yaml`, `.../role/rancher/ci.yaml`. ## Prerequisite Populate `kv/service/vault/au/syd1/secret_backend/rancher/service_account/admin` with a live Rancher admin token (keys: `token`, optional `token_name`) **before** apply, exactly as litellm's `master_key` is seeded in KV. ## Merge order Part 4 of 4 (last). Requires: puppet install (#483) → deployer policy (#91) → plugin import (#92) → this. The `plan` needs the KV seed present, so seed KV first. --------- Co-authored-by: Ben Vincent <neotheo@gmail.com> Reviewed-on: #93 Co-authored-by: Ben Vincent <ben@unkin.net> Co-committed-by: Ben Vincent <ben@unkin.net>
This commit was merged in pull request #93.
This commit is contained in:
@@ -218,5 +218,26 @@ locals {
|
||||
})
|
||||
if startswith(file_path, "gpg_key/")
|
||||
}
|
||||
rancher_secret_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(basename(file_path), ".yaml") => content
|
||||
if startswith(file_path, "rancher_secret_backend/")
|
||||
}
|
||||
rancher_secret_backend_service_account = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "rancher_secret_backend_service_account/", ""), ".yaml") => merge(content, {
|
||||
name = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = dirname(replace(file_path, "rancher_secret_backend_service_account/", ""))
|
||||
})
|
||||
if startswith(file_path, "rancher_secret_backend_service_account/")
|
||||
}
|
||||
rancher_secret_backend_role = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "rancher_secret_backend_role/", ""), ".yaml") => merge(content, {
|
||||
name = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = dirname(replace(file_path, "rancher_secret_backend_role/", ""))
|
||||
})
|
||||
if startswith(file_path, "rancher_secret_backend_role/")
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
# Mounts the rancher token secrets engine at "rancher" and writes its config.
|
||||
# The plugin is registered in the catalog separately (see
|
||||
# config/plugins/vault-plugin-secrets-rancher.yaml). Seeded service-account
|
||||
# tokens live under config/rancher_secret_backend_service_account/rancher/ and
|
||||
# roles under config/rancher_secret_backend_role/rancher/.
|
||||
description: "Rancher API token engine (seeded root rotation + dynamic scoped creds)"
|
||||
rancher_url: "https://rancher.k8s.syd1.au.unkin.net"
|
||||
request_timeout_seconds: 30
|
||||
@@ -0,0 +1,9 @@
|
||||
# A role that mints short-lived Rancher tokens from the "admin" service account.
|
||||
# Reading rancher/creds/ci returns a lease-bound token deleted from Rancher on
|
||||
# revoke. Minted tokens inherit the admin service account's RBAC; only cluster
|
||||
# and TTL are scoped per-token.
|
||||
---
|
||||
service_account: admin
|
||||
description: "CI/CD ephemeral Rancher token"
|
||||
ttl: 3600 # seconds (1h)
|
||||
max_ttl: 28800 # seconds (8h)
|
||||
@@ -0,0 +1,8 @@
|
||||
# A seeded, auto-rotated Rancher service-account token on the "rancher" engine.
|
||||
# The seed token itself is sensitive and read from KV (not stored here):
|
||||
# kv/service/vault/au/syd1/secret_backend/rancher/service_account/admin
|
||||
# -> keys: token (required), token_name (optional)
|
||||
# Populate that KV path with a live Rancher admin token BEFORE applying; the
|
||||
# engine then rotates it (mints a fresh 90d token every 45d) so it never lapses.
|
||||
token_ttl: 7776000 # 90d in seconds
|
||||
rotation_period: 3888000 # 45d in seconds
|
||||
Reference in New Issue
Block a user