## Why
CI installs vault by shelling out to `dnf install vault -y`. That reads
metadata for every enabled repo (appstream/baseos/crb/epel/ha) and downloads
the 169MB vendored vault RPM from the `unkin` repo on **every** plan/apply run
(~39s per job measured in `almalinux9-opentofu:20260606`).
## Change
- Replace `dnf install vault -y` with a pinned `curl` of the upstream vault zip
from the artifactapi `hashicorp-releases` remote proxy, extracted with the
image's `python3` (`python3 -m zipfile`) to `/usr/local/bin/vault`.
- Pin the version via a new `VAULT_VERSION` env var (`1.20.0`); bump the var to
upgrade.
## Speedup
Measured in `git.unkin.net/unkin/almalinux9-opentofu:20260606`:
| approach | time |
|---|---|
| `dnf install vault -y` (current) | ~39s |
| `dnf --disablerepo='*' --enablerepo=unkin` (still pulls 169MB RPM) | ~9s |
| curl zip from artifactapi + python extract (this PR) | ~6.6s |
~32s saved per plan/apply job. The zip is cached by artifactapi after first
fetch (warm ~3s).
## Caveats
- Assumes the `almalinux9-opentofu` image ships `curl` + `python3` (both
present in `:20260606`).
- Relies on the existing artifactapi `hashicorp-releases` generic remote whose
patterns already allow `vault/.*vault_.*_linux_amd64.zip`.
---------
Co-authored-by: benvin <neotheo@gmail.com>
Reviewed-on: #99
Co-authored-by: Ben Vincent <ben@unkin.net>
Co-committed-by: Ben Vincent <ben@unkin.net>