vault: temporarily remove ghp secret backend + roles (unblock apply)
The master apply aborts reading the unseeded ghp config KV (kv/data/service/vault/au/syd1/secret_backend/ghp/config), blocking all changes including the arrstack plugin registration (#125). The ghp backend and role are not-yet-created (0 to destroy), so removing them is non-destructive and lets the apply proceed. The ghp plugin registration and ghp policies are retained. This is part 1 of remove -> grant write policy -> seed KV -> re-add; it will be reverted once the ghp config is seeded. - Remove module.ghp_secret_backend and module.ghp_secret_backend_role instantiations (and the role's depends_on) from modules/vault_cluster/main.tf. - Remove the ghp_secret_backend and ghp_secret_backend_role variables from modules/vault_cluster/variables.tf. - Remove the ghp_secret_backend and ghp_secret_backend_role parsing blocks from config/config.hcl. - Remove the ghp_secret_backend and ghp_secret_backend_role inputs from environments/au/syd1/terragrunt.hcl. - Delete config/ghp_secret_backend/ghp.yaml and config/ghp_secret_backend_role/ghp/agent.yaml.
This commit is contained in:
@@ -536,43 +536,6 @@ module "netbox_secret_backend_role" {
|
||||
depends_on = [module.netbox_secret_backend, module.netbox_user_management]
|
||||
}
|
||||
|
||||
module "ghp_secret_backend" {
|
||||
source = "./modules/ghp_secret_backend"
|
||||
|
||||
for_each = var.ghp_secret_backend
|
||||
|
||||
path = each.key
|
||||
plugin = each.value.plugin
|
||||
description = each.value.description
|
||||
base_url = each.value.base_url
|
||||
country = var.country
|
||||
region = var.region
|
||||
ca_cert = each.value.ca_cert
|
||||
tls_skip_verify = each.value.tls_skip_verify
|
||||
request_timeout_seconds = each.value.request_timeout_seconds
|
||||
|
||||
depends_on = [module.plugin]
|
||||
}
|
||||
|
||||
module "ghp_secret_backend_role" {
|
||||
source = "./modules/ghp_secret_backend_role"
|
||||
|
||||
for_each = var.ghp_secret_backend_role
|
||||
|
||||
backend = each.value.backend
|
||||
name = each.value.name
|
||||
token_type = each.value.token_type
|
||||
installation_id = each.value.installation_id
|
||||
app_record_id = each.value.app_record_id
|
||||
repositories = each.value.repositories
|
||||
scopes = each.value.scopes
|
||||
session_prefix = each.value.session_prefix
|
||||
ttl = each.value.ttl
|
||||
max_ttl = each.value.max_ttl
|
||||
|
||||
depends_on = [module.ghp_secret_backend]
|
||||
}
|
||||
|
||||
module "vault_policy" {
|
||||
source = "./modules/vault_policy"
|
||||
|
||||
|
||||
@@ -468,36 +468,6 @@ variable "netbox_backend_aliases" {
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "ghp_secret_backend" {
|
||||
description = "Map of ghp token secret engines to create (mount + config; seeded service token read from KV)"
|
||||
type = map(object({
|
||||
plugin = optional(string, "vault-plugin-secrets-ghp")
|
||||
description = optional(string)
|
||||
base_url = string
|
||||
ca_cert = optional(string)
|
||||
tls_skip_verify = optional(bool, false)
|
||||
request_timeout_seconds = optional(number, 30)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "ghp_secret_backend_role" {
|
||||
description = "Map of ghp engine roles; reading ghp/creds/<name> mints a short-lived scoped ghp token"
|
||||
type = map(object({
|
||||
name = string
|
||||
backend = string
|
||||
token_type = optional(string)
|
||||
installation_id = optional(number)
|
||||
app_record_id = optional(string)
|
||||
repositories = optional(list(string))
|
||||
scopes = optional(list(string))
|
||||
session_prefix = optional(string)
|
||||
ttl = optional(number)
|
||||
max_ttl = optional(number)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "policy_auth_map" {
|
||||
description = "Map of auth mounts -> auth roles -> policy names"
|
||||
type = map(map(list(string)))
|
||||
|
||||
Reference in New Issue
Block a user