Mount the rancher secrets engine + seed a service account + roles (#93)
ci/woodpecker/push/apply Pipeline was successful
ci/woodpecker/push/apply Pipeline was successful
## Why Deploy the new Rancher token secrets engine into the cluster (the last of the 4 wiring PRs), mirroring the litellm/gpg pattern. Users can then `vault read rancher/creds/<role>` for short-lived, cluster-scoped Rancher tokens, backed by a seeded admin token the engine auto-rotates before Rancher's 90-day cap. ## Changes - Add `rancher_secret_backend` module — mount + config via the ranchervaultsecret provider (rancher_url `https://rancher.k8s.syd1.au.unkin.net`). - Add `rancher_secret_backend_service_account` module — seeds an auto-rotated token (90d TTL / 45d rotation); the seed token is read from KV, not git. - Add `rancher_secret_backend_role` module + a `ci` role (1h/8h, cluster+TTL scoped). - Wire `config.hcl` discovery, module variables, `main.tf` blocks, terragrunt inputs, and the `rancher` provider in `root.hcl`. - Config: `config/rancher_secret_backend/rancher.yaml`, `.../service_account/rancher/admin.yaml`, `.../role/rancher/ci.yaml`. ## Prerequisite Populate `kv/service/vault/au/syd1/secret_backend/rancher/service_account/admin` with a live Rancher admin token (keys: `token`, optional `token_name`) **before** apply, exactly as litellm's `master_key` is seeded in KV. ## Merge order Part 4 of 4 (last). Requires: puppet install (#483) → deployer policy (#91) → plugin import (#92) → this. The `plan` needs the KV seed present, so seed KV first. --------- Co-authored-by: Ben Vincent <neotheo@gmail.com> Reviewed-on: #93 Co-authored-by: Ben Vincent <ben@unkin.net> Co-committed-by: Ben Vincent <ben@unkin.net>
This commit was merged in pull request #93.
This commit is contained in:
@@ -374,6 +374,53 @@ module "gpg_key" {
|
||||
depends_on = [module.gpg_secret_backend]
|
||||
}
|
||||
|
||||
module "rancher_secret_backend" {
|
||||
source = "./modules/rancher_secret_backend"
|
||||
|
||||
for_each = var.rancher_secret_backend
|
||||
|
||||
path = each.key
|
||||
plugin = each.value.plugin
|
||||
description = each.value.description
|
||||
rancher_url = each.value.rancher_url
|
||||
ca_cert = each.value.ca_cert
|
||||
tls_skip_verify = each.value.tls_skip_verify
|
||||
request_timeout_seconds = each.value.request_timeout_seconds
|
||||
|
||||
depends_on = [module.plugin]
|
||||
}
|
||||
|
||||
module "rancher_secret_backend_service_account" {
|
||||
source = "./modules/rancher_secret_backend_service_account"
|
||||
|
||||
for_each = var.rancher_secret_backend_service_account
|
||||
|
||||
backend = each.value.backend
|
||||
name = each.value.name
|
||||
country = var.country
|
||||
region = var.region
|
||||
token_ttl = each.value.token_ttl
|
||||
rotation_period = each.value.rotation_period
|
||||
|
||||
depends_on = [module.rancher_secret_backend]
|
||||
}
|
||||
|
||||
module "rancher_secret_backend_role" {
|
||||
source = "./modules/rancher_secret_backend_role"
|
||||
|
||||
for_each = var.rancher_secret_backend_role
|
||||
|
||||
backend = each.value.backend
|
||||
name = each.value.name
|
||||
service_account = each.value.service_account
|
||||
cluster_name = each.value.cluster_name
|
||||
description = each.value.description
|
||||
ttl = each.value.ttl
|
||||
max_ttl = each.value.max_ttl
|
||||
|
||||
depends_on = [module.rancher_secret_backend_service_account]
|
||||
}
|
||||
|
||||
module "vault_policy" {
|
||||
source = "./modules/vault_policy"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user