Bump vault-secrets-arrstack provider to 0.2.0 and plumb methods
Engine plugin v0.2.0 (catalog bumped in #144) added a methods field to arrstack roles, pinning a minted arrproxy key to a set of HTTP methods. Provider v0.2.0 exposes it as an optional set attribute, but the module had no input for it, so no role yaml could use it. - Bumps the vault-secrets-arrstack provider pin from 0.1.1 to 0.2.0 in root.hcl and both arrstack modules - Adds an optional methods input to arrstack_secret_backend_role and passes it through to the resource - Threads methods through the vault_cluster arrstack_secret_backend_role object type so a role yaml may carry a methods: list methods defaults to null rather than [], matching the provider's null read-back for an unrestricted role, so existing role yamls need no change and plan stays a provider-version-only diff.
This commit is contained in:
@@ -67,7 +67,7 @@ terraform {
|
||||
}
|
||||
arrstack = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/vault-secrets-arrstack"
|
||||
version = "0.1.1"
|
||||
version = "0.2.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -370,6 +370,7 @@ module "arrstack_secret_backend_role" {
|
||||
name = each.value.name
|
||||
backend = each.value.backend
|
||||
apps = each.value.apps
|
||||
methods = each.value.methods
|
||||
ttl = each.value.ttl
|
||||
max_ttl = each.value.max_ttl
|
||||
|
||||
|
||||
@@ -7,7 +7,7 @@ terraform {
|
||||
}
|
||||
arrstack = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/vault-secrets-arrstack"
|
||||
version = "0.1.1"
|
||||
version = "0.2.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -2,6 +2,7 @@ resource "arrstack_secret_backend_role" "this" {
|
||||
backend = var.backend
|
||||
name = var.name
|
||||
apps = var.apps
|
||||
methods = var.methods
|
||||
ttl = var.ttl
|
||||
max_ttl = var.max_ttl
|
||||
}
|
||||
|
||||
@@ -3,7 +3,7 @@ terraform {
|
||||
required_providers {
|
||||
arrstack = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/vault-secrets-arrstack"
|
||||
version = "0.1.1"
|
||||
version = "0.2.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -13,6 +13,13 @@ variable "apps" {
|
||||
type = list(string)
|
||||
}
|
||||
|
||||
variable "methods" {
|
||||
description = "HTTP methods a generated key is limited to (subset of GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS). Null leaves the role unrestricted"
|
||||
type = set(string)
|
||||
# null, not [], so a role yaml that omits methods matches the provider's null read-back and shows no drift.
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "ttl" {
|
||||
description = "Default lease TTL in seconds for keys generated from this role"
|
||||
type = number
|
||||
|
||||
@@ -334,6 +334,7 @@ variable "arrstack_secret_backend_role" {
|
||||
name = string
|
||||
backend = string
|
||||
apps = list(string)
|
||||
methods = optional(set(string))
|
||||
ttl = optional(number)
|
||||
max_ttl = optional(number)
|
||||
}))
|
||||
|
||||
Reference in New Issue
Block a user