vault: temporarily remove ghp secret backend + roles (unblock apply)
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful

The master apply aborts reading the unseeded ghp config KV
(kv/data/service/vault/au/syd1/secret_backend/ghp/config), blocking all
changes including the arrstack plugin registration (#125). The ghp backend
and role are not-yet-created (0 to destroy), so removing them is
non-destructive and lets the apply proceed.

The ghp plugin registration and ghp policies are retained. This is part 1
of remove -> grant write policy -> seed KV -> re-add; it will be reverted
once the ghp config is seeded.

- Remove module.ghp_secret_backend and module.ghp_secret_backend_role
  instantiations (and the role's depends_on) from modules/vault_cluster/main.tf.
- Remove the ghp_secret_backend and ghp_secret_backend_role variables from
  modules/vault_cluster/variables.tf.
- Remove the ghp_secret_backend and ghp_secret_backend_role parsing blocks
  from config/config.hcl.
- Remove the ghp_secret_backend and ghp_secret_backend_role inputs from
  environments/au/syd1/terragrunt.hcl.
- Delete config/ghp_secret_backend/ghp.yaml and
  config/ghp_secret_backend_role/ghp/agent.yaml.
This commit is contained in:
2026-08-19 22:41:57 +10:00
parent df0510e33b
commit bb4db3e069
6 changed files with 0 additions and 113 deletions
-37
View File
@@ -536,43 +536,6 @@ module "netbox_secret_backend_role" {
depends_on = [module.netbox_secret_backend, module.netbox_user_management]
}
module "ghp_secret_backend" {
source = "./modules/ghp_secret_backend"
for_each = var.ghp_secret_backend
path = each.key
plugin = each.value.plugin
description = each.value.description
base_url = each.value.base_url
country = var.country
region = var.region
ca_cert = each.value.ca_cert
tls_skip_verify = each.value.tls_skip_verify
request_timeout_seconds = each.value.request_timeout_seconds
depends_on = [module.plugin]
}
module "ghp_secret_backend_role" {
source = "./modules/ghp_secret_backend_role"
for_each = var.ghp_secret_backend_role
backend = each.value.backend
name = each.value.name
token_type = each.value.token_type
installation_id = each.value.installation_id
app_record_id = each.value.app_record_id
repositories = each.value.repositories
scopes = each.value.scopes
session_prefix = each.value.session_prefix
ttl = each.value.ttl
max_ttl = each.value.max_ttl
depends_on = [module.ghp_secret_backend]
}
module "vault_policy" {
source = "./modules/vault_policy"
-30
View File
@@ -468,36 +468,6 @@ variable "netbox_backend_aliases" {
default = {}
}
variable "ghp_secret_backend" {
description = "Map of ghp token secret engines to create (mount + config; seeded service token read from KV)"
type = map(object({
plugin = optional(string, "vault-plugin-secrets-ghp")
description = optional(string)
base_url = string
ca_cert = optional(string)
tls_skip_verify = optional(bool, false)
request_timeout_seconds = optional(number, 30)
}))
default = {}
}
variable "ghp_secret_backend_role" {
description = "Map of ghp engine roles; reading ghp/creds/<name> mints a short-lived scoped ghp token"
type = map(object({
name = string
backend = string
token_type = optional(string)
installation_id = optional(number)
app_record_id = optional(string)
repositories = optional(list(string))
scopes = optional(list(string))
session_prefix = optional(string)
ttl = optional(number)
max_ttl = optional(number)
}))
default = {}
}
variable "policy_auth_map" {
description = "Map of auth mounts -> auth roles -> policy names"
type = map(map(list(string)))