Compare commits
160 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| ecee4b4432 | |||
| 9e2c21131f | |||
| bbde79d2a6 | |||
| f2c54888de | |||
| 36d7afbb65 | |||
| c33dcdc447 | |||
| be9bd96cf3 | |||
| bb5f6922fa | |||
| 346cf9fa43 | |||
| 1288057b81 | |||
| 3876fa818d | |||
| a548bf1cb1 | |||
| 93ba86baf3 | |||
| 098830c10b | |||
| 9cbac6d3ef | |||
| 73aaaaeb99 | |||
| 7c60a5fd53 | |||
| 27f12f183e | |||
| c61434b692 | |||
| 172ceac2fc | |||
| 48a4fd0dd1 | |||
| 4dc09547ef | |||
| 546a9efe44 | |||
| 679cec4bc1 | |||
| 71789f9f32 | |||
| 4cbcec58d3 | |||
| 9c93e185f8 | |||
| d6c8474bd3 | |||
| 42351000ee | |||
| f7d1330c37 | |||
| d9e07e432e | |||
| 14a258de7d | |||
| be8bcc3743 | |||
| dc257b1bcd | |||
| 66119e5207 | |||
| 9e6de4dc32 | |||
| 7cafafd483 | |||
| c94b2af196 | |||
| dd44146d88 | |||
| 18a62332f6 | |||
| 8fa68e2670 | |||
| 4cad39989f | |||
| c825962490 | |||
| 51bc3fffc0 | |||
| dca26029c0 | |||
| d398911108 | |||
| c093d5830d | |||
| 4b176846f2 | |||
| 90b765d713 | |||
| 3fb5a64a17 | |||
| 33a746e545 | |||
| 4fe0e0de73 | |||
| a47f841028 | |||
| 9192879c03 | |||
| 5cdf6b410d | |||
| b51617c009 | |||
| 66ee6430fa | |||
| fd03727ec2 | |||
| 5536869a38 | |||
| f8f1185b42 | |||
| 75e9db1aa6 | |||
| f47804ffdf | |||
| 24c124d6eb | |||
| 9d54b4cfcc | |||
| 33af7010fb | |||
| cb1b383035 | |||
| f6d06cb319 | |||
| 1c9e063310 | |||
| 8070b6f66b | |||
| b115b7d28a | |||
| 25e3d48337 | |||
| fdc801739f | |||
| 56d858f900 | |||
| bd112181f5 | |||
| 4f185d5e28 | |||
| 65ad53e24c | |||
| d217f6e42d | |||
| 9814b8fc1a | |||
| 7b81abfa9e | |||
| 2466a6fe5c | |||
| c88b19a216 | |||
| 3bada72838 | |||
| 8961ba3748 | |||
| 26b3ee84d6 | |||
| 0776fac6eb | |||
| 3a2ecc9b23 | |||
| 5afd1ad9c1 | |||
| 756286c231 | |||
| 9cc482d471 | |||
| 6624f7aed1 | |||
| ad1118af85 | |||
| cafa887cdc | |||
| f10f96d19c | |||
| da0e0e4239 | |||
| 2efbf7cc6e | |||
| b9deb02cfb | |||
| 391c77d30b | |||
| 6353ac6bbc | |||
| 605aa204a9 | |||
| 4cf1b43960 | |||
| f217dbaeca | |||
| 7814551084 | |||
| 85cda88a3b | |||
| 02654ac32a | |||
| c3c1cb660a | |||
| 5cbd5815a0 | |||
| 6d84efe81e | |||
| 9ff6cf7de7 | |||
| 865a97ba0e | |||
| c0d0888172 | |||
| 49889eaf22 | |||
| d2acaeb7bc | |||
| cbee19b5f9 | |||
| 353d726510 | |||
| 537cc9013a | |||
| 8e1d242dba | |||
| 85d81fef72 | |||
| 59b7b01c23 | |||
| 5675a469da | |||
| 489969fed8 | |||
| 1ee07dd52f | |||
| 0869b6f723 | |||
| bc9b4eebdc | |||
| 9f4b77a765 | |||
| 4364b444fd | |||
| fee61c3eb5 | |||
| 23e3fb88ea | |||
| 8fd8913554 | |||
| 1f35fec37c | |||
| b46d36d03b | |||
| ac36f9355c | |||
| 50d1e31ea5 | |||
| d508dcd4a9 | |||
| 4aac926c6a | |||
| 05268f9dd8 | |||
| 80c14ef4e4 | |||
| feee7a265e | |||
| 8bc67e1e5b | |||
| 275b640adc | |||
| 2dc37cc8c4 | |||
| 9b9afdce58 | |||
| cd9c006203 | |||
| 2d345cc63b | |||
| 99b643b458 | |||
| f83ba13158 | |||
| e4d80e42dc | |||
| 12e04b3db7 | |||
| aa518c1b44 | |||
| fc22ac1711 | |||
| d5bd00d8ab | |||
| 63dd355311 | |||
| bfda3f2f72 | |||
| f597e0a979 | |||
| fd0fe2403b | |||
| bcdb81e060 | |||
| 9e3cbce264 | |||
| f78416361b | |||
| 582f38c68f | |||
| 7b9e27cfe6 | |||
| 14790f8277 |
@@ -0,0 +1,4 @@
|
||||
.terraform
|
||||
.terraform.lock.hcl
|
||||
env
|
||||
.terragrunt-cache
|
||||
@@ -0,0 +1,24 @@
|
||||
repos:
|
||||
- repo: https://github.com/pre-commit/pre-commit-hooks
|
||||
rev: v4.4.0
|
||||
hooks:
|
||||
- id: end-of-file-fixer
|
||||
types: [yaml]
|
||||
- id: trailing-whitespace
|
||||
types: [yaml]
|
||||
- repo: https://github.com/gruntwork-io/pre-commit
|
||||
rev: v0.1.30
|
||||
hooks:
|
||||
- id: tofu-fmt
|
||||
- id: tofu-validate
|
||||
- id: tflint
|
||||
- id: terragrunt-hcl-fmt
|
||||
- repo: https://github.com/adrienverge/yamllint.git
|
||||
rev: v1.37.1
|
||||
hooks:
|
||||
- id: yamllint
|
||||
args:
|
||||
[
|
||||
"-d {extends: relaxed, rules: {line-length: disable}, ignore: chart}",
|
||||
"-s",
|
||||
]
|
||||
@@ -0,0 +1,23 @@
|
||||
when:
|
||||
- event: push
|
||||
branch: master
|
||||
|
||||
steps:
|
||||
- name: apply
|
||||
image: git.unkin.net/unkin/almalinux9-opentofu:20260606
|
||||
environment:
|
||||
VAULT_AUTH_METHOD: kubernetes
|
||||
commands:
|
||||
- dnf install vault -y
|
||||
- make plan
|
||||
- make apply
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: terraform-vault
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
@@ -0,0 +1,21 @@
|
||||
when:
|
||||
- event: pull_request
|
||||
|
||||
steps:
|
||||
- name: plan
|
||||
image: git.unkin.net/unkin/almalinux9-opentofu:20260606
|
||||
environment:
|
||||
VAULT_AUTH_METHOD: kubernetes
|
||||
commands:
|
||||
- dnf install vault -y
|
||||
- make plan
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: terraform-vault
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
@@ -0,0 +1,18 @@
|
||||
when:
|
||||
- event: pull_request
|
||||
|
||||
steps:
|
||||
- name: pre-commit
|
||||
image: git.unkin.net/unkin/almalinux9-opentofu:20260606
|
||||
commands:
|
||||
- uvx pre-commit run --all-files
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: default
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
@@ -0,0 +1,35 @@
|
||||
.PHONY: init plan apply format
|
||||
|
||||
VAULT_AUTH_METHOD ?= approle
|
||||
VAULT_K8S_ROLE ?= woodpecker_terraform_vault
|
||||
VAULT_K8S_MOUNT ?= auth/k8s/au/syd1
|
||||
VAULT_K8S_JWT_PATH ?= /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||
|
||||
# Define vault_env function to set up vault environment
|
||||
define vault_env
|
||||
@export VAULT_ADDR="https://vault.service.consul:8200" && \
|
||||
if [ "$(VAULT_AUTH_METHOD)" = "kubernetes" ]; then \
|
||||
export VAULT_TOKEN=$$(vault write -field=token $(VAULT_K8S_MOUNT)/login role=$(VAULT_K8S_ROLE) jwt=$$(cat $(VAULT_K8S_JWT_PATH))); \
|
||||
else \
|
||||
export VAULT_TOKEN=$$(vault write -field=token auth/approle/login role_id=$$VAULT_ROLEID); \
|
||||
fi && \
|
||||
export CONSUL_HTTP_TOKEN=$$(vault read -field=token consul_root/au/syd1/creds/terraform-vault)
|
||||
endef
|
||||
|
||||
init:
|
||||
@$(call vault_env) && \
|
||||
terragrunt run --all --non-interactive init -- -upgrade
|
||||
|
||||
plan: init
|
||||
@$(call vault_env) && \
|
||||
terragrunt run --all --parallelism 4 --non-interactive plan
|
||||
|
||||
apply: init
|
||||
@$(call vault_env) && \
|
||||
terragrunt run --all --parallelism 2 --non-interactive apply
|
||||
|
||||
format:
|
||||
@echo "Formatting OpenTofu files..."
|
||||
@tofu fmt -recursive .
|
||||
@echo "Formatting Terragrunt files..."
|
||||
@terragrunt hcl fmt
|
||||
@@ -1,3 +1,37 @@
|
||||
# terraform-vault
|
||||
|
||||
A repository to manage the configuration of Vault secret engines, authentication modes and policies.
|
||||
A repository to manage the configuration of Vault secret engines, authentication modes and policies.
|
||||
|
||||
|
||||
# Usage
|
||||
|
||||
1. Initialize Terraform
|
||||
|
||||
Once you have your backend block configured, you need to initialize your Terraform working directory to configure the backend:
|
||||
|
||||
```bash
|
||||
terraform init
|
||||
```
|
||||
|
||||
This command initializes the backend and checks the connection to Consul. If everything is set up correctly, Terraform will start using Consul as its backend for storing the state.
|
||||
|
||||
2. Common terraform init Errors
|
||||
|
||||
If you encounter errors while running terraform init, check the following:
|
||||
|
||||
Consul server is reachable: Make sure that the address is correct and that you can connect to the Consul server.
|
||||
Consul token (if using ACLs): Verify that the token has the correct permissions to write to the specified path in the Consul KV store.
|
||||
|
||||
3. Example Consul KV Structure
|
||||
|
||||
In Consul, the state file will be stored in the KV store under the specified path:
|
||||
|
||||
```bash
|
||||
terraform/state
|
||||
```
|
||||
|
||||
You can check the Consul KV store by accessing the Consul UI or using the consul kv command to see the stored Terraform state:
|
||||
|
||||
```bash
|
||||
consul kv get terraform/state
|
||||
```
|
||||
|
||||
@@ -0,0 +1,2 @@
|
||||
default_lease_ttl: 60s
|
||||
max_lease_ttl: 24h
|
||||
@@ -0,0 +1,11 @@
|
||||
token_ttl: 30
|
||||
token_max_ttl: 30
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "198.18.25.5/32"
|
||||
- "198.18.26.3/32"
|
||||
- "198.18.27.89/32"
|
||||
- "198.18.28.8/32"
|
||||
- "198.18.29.33/32"
|
||||
- "198.18.29.239/32"
|
||||
use_deterministic_role_id: false
|
||||
@@ -0,0 +1,9 @@
|
||||
token_ttl: 60
|
||||
token_max_ttl: 120
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
- "198.18.13.77/32"
|
||||
- "198.18.13.78/32"
|
||||
- "198.18.13.79/32"
|
||||
use_deterministic_role_id: false
|
||||
@@ -0,0 +1,9 @@
|
||||
token_ttl: 300
|
||||
token_max_ttl: 600
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
- "198.18.25.102/32"
|
||||
- "198.18.26.91/32"
|
||||
- "198.18.27.40/32"
|
||||
use_deterministic_role_id: false
|
||||
@@ -0,0 +1,11 @@
|
||||
token_ttl: 30
|
||||
token_max_ttl: 30
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "198.18.25.5/32"
|
||||
- "198.18.26.3/32"
|
||||
- "198.18.27.89/32"
|
||||
- "198.18.28.8/32"
|
||||
- "198.18.29.33/32"
|
||||
- "198.18.29.239/32"
|
||||
use_deterministic_role_id: false
|
||||
@@ -0,0 +1,9 @@
|
||||
token_ttl: 30
|
||||
token_max_ttl: 30
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
- "198.18.25.102/32"
|
||||
- "198.18.26.91/32"
|
||||
- "198.18.27.40/32"
|
||||
use_deterministic_role_id: false
|
||||
@@ -0,0 +1,6 @@
|
||||
token_ttl: 3600
|
||||
token_max_ttl: 14400
|
||||
bind_secret_id: true
|
||||
token_bound_cidrs:
|
||||
- "198.18.13.59/32"
|
||||
use_deterministic_role_id: false
|
||||
@@ -0,0 +1,11 @@
|
||||
token_ttl: 30
|
||||
token_max_ttl: 30
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "198.18.25.5/32"
|
||||
- "198.18.26.3/32"
|
||||
- "198.18.27.89/32"
|
||||
- "198.18.28.8/32"
|
||||
- "198.18.29.33/32"
|
||||
- "198.18.29.239/32"
|
||||
use_deterministic_role_id: false
|
||||
@@ -0,0 +1,9 @@
|
||||
token_ttl: 120
|
||||
token_max_ttl: 120
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
- "198.18.25.102/32"
|
||||
- "198.18.26.91/32"
|
||||
- "198.18.27.40/32"
|
||||
use_deterministic_role_id: true
|
||||
@@ -0,0 +1,9 @@
|
||||
token_ttl: 120
|
||||
token_max_ttl: 120
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
- "198.18.25.102/32"
|
||||
- "198.18.26.91/32"
|
||||
- "198.18.27.40/32"
|
||||
use_deterministic_role_id: true
|
||||
@@ -0,0 +1,9 @@
|
||||
token_ttl: 120
|
||||
token_max_ttl: 120
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
- "198.18.25.102/32"
|
||||
- "198.18.26.91/32"
|
||||
- "198.18.27.40/32"
|
||||
use_deterministic_role_id: true
|
||||
@@ -0,0 +1,9 @@
|
||||
token_ttl: 60
|
||||
token_max_ttl: 120
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
- "198.18.25.102/32"
|
||||
- "198.18.26.91/32"
|
||||
- "198.18.27.40/32"
|
||||
use_deterministic_role_id: false
|
||||
@@ -0,0 +1,9 @@
|
||||
token_ttl: 120
|
||||
token_max_ttl: 120
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
- "198.18.25.102/32"
|
||||
- "198.18.26.91/32"
|
||||
- "198.18.27.40/32"
|
||||
use_deterministic_role_id: true
|
||||
@@ -0,0 +1,9 @@
|
||||
token_ttl: 60
|
||||
token_max_ttl: 120
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
- "198.18.25.102/32"
|
||||
- "198.18.26.91/32"
|
||||
- "198.18.27.40/32"
|
||||
use_deterministic_role_id: true
|
||||
@@ -0,0 +1,9 @@
|
||||
token_ttl: 60
|
||||
token_max_ttl: 120
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
- "198.18.25.102/32"
|
||||
- "198.18.26.91/32"
|
||||
- "198.18.27.40/32"
|
||||
use_deterministic_role_id: false
|
||||
@@ -0,0 +1,9 @@
|
||||
token_ttl: 120
|
||||
token_max_ttl: 120
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
- "198.18.25.102/32"
|
||||
- "198.18.26.91/32"
|
||||
- "198.18.27.40/32"
|
||||
use_deterministic_role_id: true
|
||||
@@ -0,0 +1,9 @@
|
||||
token_ttl: 120
|
||||
token_max_ttl: 120
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
- "198.18.25.102/32"
|
||||
- "198.18.26.91/32"
|
||||
- "198.18.27.40/32"
|
||||
use_deterministic_role_id: true
|
||||
@@ -0,0 +1,9 @@
|
||||
token_ttl: 60
|
||||
token_max_ttl: 120
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
- "198.18.25.102/32"
|
||||
- "198.18.26.91/32"
|
||||
- "198.18.27.40/32"
|
||||
use_deterministic_role_id: false
|
||||
@@ -0,0 +1,9 @@
|
||||
token_ttl: 120
|
||||
token_max_ttl: 120
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
- "198.18.25.102/32"
|
||||
- "198.18.26.91/32"
|
||||
- "198.18.27.40/32"
|
||||
use_deterministic_role_id: true
|
||||
@@ -0,0 +1,6 @@
|
||||
token_ttl: 60
|
||||
token_max_ttl: 120
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
use_deterministic_role_id: false
|
||||
@@ -0,0 +1,5 @@
|
||||
kubernetes_host: https://api-k8s.service.consul:6443
|
||||
disable_iss_validation: true
|
||||
use_annotations_as_alias_metadata: false # doesnt work with openbao yet
|
||||
default_lease_ttl: 1h
|
||||
max_lease_ttl: 24h
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- default
|
||||
bound_service_account_namespaces:
|
||||
- artifactapi
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: vault
|
||||
@@ -0,0 +1,9 @@
|
||||
bound_service_account_names:
|
||||
- ceph-csi-rbd-csi-rbd-provisioner
|
||||
- ceph-csi-cephfs-csi-cephfs-provisioner
|
||||
bound_service_account_namespaces:
|
||||
- csi-cephrbd
|
||||
- csi-cephfs
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: vault
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- cert-manager-vault-issuer
|
||||
bound_service_account_namespaces:
|
||||
- cert-manager
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: vault
|
||||
@@ -0,0 +1,6 @@
|
||||
bound_service_account_names:
|
||||
- default
|
||||
bound_service_account_namespaces: ['*']
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: vault
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- externaldns
|
||||
bound_service_account_namespaces:
|
||||
- externaldns
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: vault
|
||||
@@ -0,0 +1,6 @@
|
||||
bound_service_account_names:
|
||||
- default
|
||||
bound_service_account_namespaces:
|
||||
- huntarr
|
||||
token_ttl: 600
|
||||
audience: vault
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- default
|
||||
bound_service_account_namespaces:
|
||||
- identity
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: vault
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- media-apps-vault-reader
|
||||
bound_service_account_namespaces:
|
||||
- media-apps
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: vault
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- default
|
||||
bound_service_account_namespaces:
|
||||
- puppet
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: vault
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- rancher
|
||||
bound_service_account_namespaces:
|
||||
- cattle-system
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: vault
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- default
|
||||
bound_service_account_namespaces:
|
||||
- repoflow
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: vault
|
||||
@@ -0,0 +1,8 @@
|
||||
# rpmbuilder is deployed in woodpeckerci
|
||||
bound_service_account_names:
|
||||
- default
|
||||
bound_service_account_namespaces:
|
||||
- woodpecker
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: https://kubernetes.default.svc.cluster.local
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- default
|
||||
bound_service_account_namespaces:
|
||||
- woodpecker
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: vault
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- terraform-artifactapi
|
||||
bound_service_account_namespaces:
|
||||
- woodpecker
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: https://kubernetes.default.svc.cluster.local
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- terraform-authentik
|
||||
bound_service_account_namespaces:
|
||||
- woodpecker
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: https://kubernetes.default.svc.cluster.local
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- terraform-git
|
||||
bound_service_account_namespaces:
|
||||
- woodpecker
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: https://kubernetes.default.svc.cluster.local
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- terraform-prowlarr
|
||||
bound_service_account_namespaces:
|
||||
- woodpecker
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: https://kubernetes.default.svc.cluster.local
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- terraform-radarr
|
||||
bound_service_account_namespaces:
|
||||
- woodpecker
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: https://kubernetes.default.svc.cluster.local
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- terraform-sonarr
|
||||
bound_service_account_namespaces:
|
||||
- woodpecker
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: https://kubernetes.default.svc.cluster.local
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- terraform-vault
|
||||
bound_service_account_namespaces:
|
||||
- woodpecker
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: https://kubernetes.default.svc.cluster.local
|
||||
@@ -0,0 +1,10 @@
|
||||
userdn: "ou=people,ou=users,dc=main,dc=unkin,dc=net"
|
||||
userattr: "uid"
|
||||
upndomain: "users.main.unkin.net"
|
||||
discoverdn: false
|
||||
groupdn: "ou=users,dc=main,dc=unkin,dc=net"
|
||||
groupfilter: "(&(objectClass=posixGroup)(memberUid={{.Username}}))"
|
||||
groupattr: "uid"
|
||||
username_as_alias: true
|
||||
default_lease_ttl: 24h
|
||||
max_lease_ttl: 168h
|
||||
@@ -0,0 +1,3 @@
|
||||
---
|
||||
# this file doesnt need anything in it, so this data is just to make sure yamlencode reads some yaml data
|
||||
description: foo
|
||||
@@ -0,0 +1,3 @@
|
||||
---
|
||||
# this file doesnt need anything in it, so this data is just to make sure yamlencode reads some yaml data
|
||||
description: foo
|
||||
@@ -0,0 +1,3 @@
|
||||
---
|
||||
# this file doesnt need anything in it, so this data is just to make sure yamlencode reads some yaml data
|
||||
description: foo
|
||||
@@ -0,0 +1,3 @@
|
||||
---
|
||||
# this file doesnt need anything in it, so this data is just to make sure yamlencode reads some yaml data
|
||||
description: foo
|
||||
@@ -0,0 +1,202 @@
|
||||
# =============================================================================
|
||||
# VAULT MODULE CONFIGURATION SYSTEM
|
||||
# =============================================================================
|
||||
#
|
||||
# This file automatically discovers and organizes YAML configuration files
|
||||
# for Vault modules, creating structured configuration maps for Terraform.
|
||||
#
|
||||
# HOW IT WORKS:
|
||||
# 1. Scans all subdirectories for *.yaml files
|
||||
# 2. Groups files by module type based on directory structure
|
||||
# 3. Creates unique resource keys to prevent naming conflicts
|
||||
# 4. Adds computed fields like name, backend, etc. from file paths
|
||||
#
|
||||
# DIRECTORY STRUCTURE:
|
||||
# config/
|
||||
# ├── auth_approle_role/
|
||||
# │ └── approle/
|
||||
# │ ├── certmanager.yaml # Creates key: "approle/certmanager"
|
||||
# │ └── myapp.yaml # Creates key: "approle/myapp"
|
||||
# ├── auth_kubernetes_role/
|
||||
# │ └── k8s/au/syd1/
|
||||
# │ ├── default.yaml # Creates key: "k8s/au/syd1/default"
|
||||
# │ └── myapp.yaml # Creates key: "k8s/au/syd1/myapp"
|
||||
# └── kv_secret_backend/
|
||||
# ├── kv.yaml # Creates key: "kv"
|
||||
# └── secrets.yaml # Creates key: "secrets"
|
||||
#
|
||||
# EXAMPLE YAML FILE (config/auth_approle_role/approle/myapp.yaml):
|
||||
# ```yaml
|
||||
# token_ttl: 3600
|
||||
# token_max_ttl: 7200
|
||||
# bind_secret_id: true
|
||||
# token_bound_cidrs:
|
||||
# - "10.0.0.0/8"
|
||||
# ```
|
||||
#
|
||||
# This becomes:
|
||||
# ```hcl
|
||||
# auth_approle_role = {
|
||||
# "approle/myapp" = {
|
||||
# approle_name = "myapp" # Auto-computed from filename
|
||||
# mount_path = "approle" # Auto-computed from directory
|
||||
# token_ttl = 3600 # From YAML content
|
||||
# token_max_ttl = 7200 # From YAML content
|
||||
# bind_secret_id = true # From YAML content
|
||||
# token_bound_cidrs = ["10.0.0.0/8"]
|
||||
# }
|
||||
# }
|
||||
# ```
|
||||
#
|
||||
# KEY NAMING PATTERNS:
|
||||
# - Simple backends: filename only (e.g., "kv", "transit")
|
||||
# - Role-based resources: full path without extension (e.g., "approle/myapp")
|
||||
# - This ensures uniqueness when multiple backends have similar role names
|
||||
#
|
||||
# GENERATED OUTPUTS:
|
||||
# - config.auth_approle_backend, config.auth_approle_role, etc.
|
||||
# - Each module gets its own map with properly structured configuration
|
||||
#
|
||||
# =============================================================================
|
||||
|
||||
locals {
|
||||
# Find all YAML files in subdirectories
|
||||
config_files = fileset(".", "**/*.yaml")
|
||||
|
||||
# Create a flat map of all files with their content
|
||||
all_configs = {
|
||||
for file_path in local.config_files :
|
||||
file_path => yamldecode(file(file_path))
|
||||
}
|
||||
|
||||
# Group by module directory (first part of path)
|
||||
config = {
|
||||
auth_approle_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(basename(file_path), ".yaml") => content
|
||||
if startswith(file_path, "auth_approle_backend/")
|
||||
}
|
||||
auth_approle_role = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "auth_approle_role/", ""), ".yaml") => merge(content, {
|
||||
approle_name = trimsuffix(basename(file_path), ".yaml")
|
||||
mount_path = split("/", replace(file_path, "auth_approle_role/", ""))[0]
|
||||
})
|
||||
if startswith(file_path, "auth_approle_role/")
|
||||
}
|
||||
auth_ldap_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(basename(file_path), ".yaml") => content
|
||||
if startswith(file_path, "auth_ldap_backend/")
|
||||
}
|
||||
auth_ldap_group = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "auth_ldap_group/", ""), ".yaml") => merge(content, {
|
||||
groupname = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = split("/", replace(file_path, "auth_ldap_group/", ""))[0]
|
||||
})
|
||||
if startswith(file_path, "auth_ldap_group/")
|
||||
}
|
||||
auth_kubernetes_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "auth_kubernetes_backend/", ""), ".yaml") => content
|
||||
if startswith(file_path, "auth_kubernetes_backend/")
|
||||
}
|
||||
auth_kubernetes_role = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "auth_kubernetes_role/", ""), ".yaml") => merge(content, {
|
||||
role_name = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = dirname(replace(file_path, "auth_kubernetes_role/", ""))
|
||||
})
|
||||
if startswith(file_path, "auth_kubernetes_role/")
|
||||
}
|
||||
kv_secret_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(basename(file_path), ".yaml") => content
|
||||
if startswith(file_path, "kv_secret_backend/")
|
||||
}
|
||||
transit_secret_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(basename(file_path), ".yaml") => content
|
||||
if startswith(file_path, "transit_secret_backend/")
|
||||
}
|
||||
transit_secret_backend_key = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "transit_secret_backend_key/", ""), ".yaml") => merge(content, {
|
||||
name = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = dirname(replace(file_path, "transit_secret_backend_key/", ""))
|
||||
})
|
||||
if startswith(file_path, "transit_secret_backend_key/")
|
||||
}
|
||||
ssh_secret_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(basename(file_path), ".yaml") => content
|
||||
if startswith(file_path, "ssh_secret_backend/")
|
||||
}
|
||||
ssh_secret_backend_role = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "ssh_secret_backend_role/", ""), ".yaml") => merge(content, {
|
||||
name = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = dirname(replace(file_path, "ssh_secret_backend_role/", ""))
|
||||
})
|
||||
if startswith(file_path, "ssh_secret_backend_role/")
|
||||
}
|
||||
pki_secret_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "pki_secret_backend/", ""), ".yaml") => content
|
||||
if startswith(file_path, "pki_secret_backend/")
|
||||
}
|
||||
pki_secret_backend_role = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "pki_secret_backend_role/", ""), ".yaml") => merge(content, {
|
||||
name = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = dirname(replace(file_path, "pki_secret_backend_role/", ""))
|
||||
})
|
||||
if startswith(file_path, "pki_secret_backend_role/")
|
||||
}
|
||||
kubernetes_secret_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "kubernetes_secret_backend/", ""), ".yaml") => content
|
||||
if startswith(file_path, "kubernetes_secret_backend/")
|
||||
}
|
||||
kubernetes_secret_backend_role = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "kubernetes_secret_backend_role/", ""), ".yaml") => merge(content, {
|
||||
name = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = dirname(replace(file_path, "kubernetes_secret_backend_role/", ""))
|
||||
})
|
||||
if startswith(file_path, "kubernetes_secret_backend_role/")
|
||||
}
|
||||
consul_secret_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "consul_secret_backend/", ""), ".yaml") => content
|
||||
if startswith(file_path, "consul_secret_backend/")
|
||||
}
|
||||
consul_secret_backend_role = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "consul_secret_backend_role/", ""), ".yaml") => merge(content, {
|
||||
name = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = dirname(replace(file_path, "consul_secret_backend_role/", ""))
|
||||
})
|
||||
if startswith(file_path, "consul_secret_backend_role/")
|
||||
}
|
||||
pki_mount_only = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(basename(file_path), ".yaml") => content
|
||||
if startswith(file_path, "pki_mount_only/")
|
||||
}
|
||||
litellm_secret_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(basename(file_path), ".yaml") => content
|
||||
if startswith(file_path, "litellm_secret_backend/")
|
||||
}
|
||||
litellm_secret_backend_role = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "litellm_secret_backend_role/", ""), ".yaml") => merge(content, {
|
||||
name = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = dirname(replace(file_path, "litellm_secret_backend_role/", ""))
|
||||
})
|
||||
if startswith(file_path, "litellm_secret_backend_role/")
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,7 @@
|
||||
description: "consul secret engine for au-syd1 cluster"
|
||||
default_lease_ttl_seconds: 600
|
||||
max_lease_ttl_seconds: 86400
|
||||
address: "consul.service.au-syd1.consul"
|
||||
scheme: https
|
||||
bootstrap: false
|
||||
datacenter: au-syd1
|
||||
@@ -0,0 +1,5 @@
|
||||
consul_roles:
|
||||
- terraform-artifactapi
|
||||
ttl: 120
|
||||
max_ttl: 300
|
||||
datacenters: []
|
||||
@@ -0,0 +1,5 @@
|
||||
consul_roles:
|
||||
- terraform-authentik
|
||||
ttl: 120
|
||||
max_ttl: 300
|
||||
datacenters: []
|
||||
@@ -0,0 +1,5 @@
|
||||
consul_roles:
|
||||
- terraform-git
|
||||
ttl: 120
|
||||
max_ttl: 300
|
||||
datacenters: []
|
||||
@@ -0,0 +1,5 @@
|
||||
consul_roles:
|
||||
- terraform-incus
|
||||
ttl: 300
|
||||
max_ttl: 600
|
||||
datacenters: []
|
||||
@@ -0,0 +1,5 @@
|
||||
consul_roles:
|
||||
- terraform-k8s
|
||||
ttl: 120
|
||||
max_ttl: 300
|
||||
datacenters: []
|
||||
@@ -0,0 +1,5 @@
|
||||
consul_roles:
|
||||
- terraform-ldap
|
||||
ttl: 60
|
||||
max_ttl: 60
|
||||
datacenters: []
|
||||
@@ -0,0 +1,5 @@
|
||||
consul_roles:
|
||||
- terraform-nomad
|
||||
ttl: 120
|
||||
max_ttl: 300
|
||||
datacenters: []
|
||||
@@ -0,0 +1,5 @@
|
||||
consul_roles:
|
||||
- terraform-prowlarr
|
||||
ttl: 120
|
||||
max_ttl: 300
|
||||
datacenters: []
|
||||
@@ -0,0 +1,5 @@
|
||||
consul_roles:
|
||||
- terraform-radarr
|
||||
ttl: 120
|
||||
max_ttl: 300
|
||||
datacenters: []
|
||||
@@ -0,0 +1,5 @@
|
||||
consul_roles:
|
||||
- terraform-repoflow
|
||||
ttl: 120
|
||||
max_ttl: 300
|
||||
datacenters: []
|
||||
@@ -0,0 +1,5 @@
|
||||
consul_roles:
|
||||
- terraform-sonarr
|
||||
ttl: 120
|
||||
max_ttl: 300
|
||||
datacenters: []
|
||||
@@ -0,0 +1,5 @@
|
||||
consul_roles:
|
||||
- terraform-vault
|
||||
ttl: 120
|
||||
max_ttl: 300
|
||||
datacenters: []
|
||||
@@ -0,0 +1,5 @@
|
||||
description: "kubernetes secret engine for au-syd1 cluster"
|
||||
default_lease_ttl_seconds: 600
|
||||
max_lease_ttl_seconds: 86400
|
||||
kubernetes_host: "https://api-k8s.service.consul:6443"
|
||||
disable_local_ca_jwt: false
|
||||
@@ -0,0 +1,4 @@
|
||||
allowed_kubernetes_namespaces:
|
||||
- "*"
|
||||
kubernetes_role_type: "ClusterRole"
|
||||
extra_labels: {}
|
||||
@@ -0,0 +1,4 @@
|
||||
allowed_kubernetes_namespaces:
|
||||
- "*"
|
||||
kubernetes_role_type: "ClusterRole"
|
||||
extra_labels: {}
|
||||
@@ -0,0 +1,4 @@
|
||||
allowed_kubernetes_namespaces:
|
||||
- "*"
|
||||
kubernetes_role_type: "ClusterRole"
|
||||
extra_labels: {}
|
||||
@@ -0,0 +1,4 @@
|
||||
allowed_kubernetes_namespaces:
|
||||
- "media-apps"
|
||||
kubernetes_role_type: "Role"
|
||||
extra_labels: {}
|
||||
@@ -0,0 +1,4 @@
|
||||
type: kv-v2
|
||||
description: "Key-Value secrets engine"
|
||||
version: "2"
|
||||
max_versions: 10
|
||||
@@ -0,0 +1,4 @@
|
||||
type: kv-v2
|
||||
description: "Rundeck secrets engine"
|
||||
version: "2"
|
||||
max_versions: 5
|
||||
@@ -0,0 +1,6 @@
|
||||
# Mounts the LiteLLM dynamic secrets engine at "litellm" and writes its config.
|
||||
# The master key is sensitive and read from KV, not stored here:
|
||||
# kv/service/vault/au/syd1/secret_backend/litellm -> key "master_key"
|
||||
description: "LiteLLM dynamic virtual keys"
|
||||
base_url: "http://litellm.litellm.svc:4000"
|
||||
request_timeout_seconds: 30
|
||||
@@ -0,0 +1,10 @@
|
||||
---
|
||||
models:
|
||||
- claude-haiku-4-5
|
||||
- claude-sonnet-4-6
|
||||
max_budget: 50
|
||||
ttl: 3600 # seconds (1h)
|
||||
max_ttl: 86400 # seconds (24h)
|
||||
metadata:
|
||||
team: mailfiltering
|
||||
env: prod
|
||||
@@ -0,0 +1,17 @@
|
||||
description: "PKI Intermediate CA"
|
||||
max_lease_ttl_seconds: 157680000 # 43800 hours * 3600
|
||||
issuer_ref: "default"
|
||||
issuing_certificates:
|
||||
- "https://vault.service.consul:8200/v1/pki_int/ca"
|
||||
crl_distribution_points:
|
||||
- "https://vault.service.consul:8200/v1/pki_int/crl"
|
||||
ocsp_servers: []
|
||||
enable_templating: false
|
||||
default_issuer_ref: null
|
||||
default_follows_latest_issuer: false
|
||||
crl_expiry: "72h"
|
||||
crl_disable: false
|
||||
ocsp_disable: false
|
||||
auto_rebuild: false
|
||||
enable_delta: false
|
||||
delta_rebuild_interval: null
|
||||
@@ -0,0 +1,17 @@
|
||||
description: "PKI Root CA"
|
||||
max_lease_ttl_seconds: 315360000 # 10 years
|
||||
issuer_ref: "default"
|
||||
issuing_certificates:
|
||||
- "https://vault.service.consul:8200/v1/pki_root/ca"
|
||||
crl_distribution_points:
|
||||
- "https://vault.service.consul:8200/v1/pki_root/crl"
|
||||
ocsp_servers: []
|
||||
enable_templating: false
|
||||
default_issuer_ref: null
|
||||
default_follows_latest_issuer: false
|
||||
crl_expiry: "72h"
|
||||
crl_disable: false
|
||||
ocsp_disable: false
|
||||
auto_rebuild: false
|
||||
enable_delta: false
|
||||
delta_rebuild_interval: null
|
||||
@@ -0,0 +1,18 @@
|
||||
description: "PKI Root CA AU SYD1"
|
||||
max_lease_ttl_seconds: 315360000 # 87600 * 3600
|
||||
common_name: "unkin.net AU SYD1 Root CA"
|
||||
issuer_name: "UNKIN_AU_SYD1_ROOTCA_2024"
|
||||
ttl: 315360000 # 87600 * 3600
|
||||
format: "pem"
|
||||
issuing_certificates:
|
||||
- "https://vault.service.consul:8200/v1/pki/au/syd1/ca"
|
||||
crl_distribution_points:
|
||||
- "https://vault.service.consul:8200/v1/pki/au/syd1/crl"
|
||||
ocsp_servers: []
|
||||
enable_templating: false
|
||||
default_follows_latest_issuer: false
|
||||
crl_expiry: "72h"
|
||||
crl_disable: false
|
||||
ocsp_disable: false
|
||||
auto_rebuild: false
|
||||
enable_delta: false
|
||||
@@ -0,0 +1,16 @@
|
||||
allow_ip_sans: true
|
||||
allowed_domains:
|
||||
- "unkin.net"
|
||||
- "*.unkin.net"
|
||||
- "localhost"
|
||||
allow_subdomains: true
|
||||
allow_glob_domains: true
|
||||
allow_bare_domains: true
|
||||
enforce_hostnames: true
|
||||
allow_any_name: true
|
||||
max_ttl: 7776000 # 2160 * 3600
|
||||
key_bits: 4096
|
||||
country:
|
||||
- "Australia"
|
||||
use_csr_common_name: true
|
||||
use_csr_sans: true
|
||||
@@ -0,0 +1,16 @@
|
||||
allow_ip_sans: true
|
||||
allowed_domains:
|
||||
- "unkin.net"
|
||||
- "*.unkin.net"
|
||||
- "localhost"
|
||||
allow_subdomains: true
|
||||
allow_glob_domains: true
|
||||
allow_bare_domains: true
|
||||
enforce_hostnames: true
|
||||
allow_any_name: true
|
||||
max_ttl: 7776000 # 2160 * 3600
|
||||
key_bits: 4096
|
||||
country:
|
||||
- "Australia"
|
||||
use_csr_common_name: true
|
||||
use_csr_sans: true
|
||||
@@ -0,0 +1,14 @@
|
||||
allow_ip_sans: true
|
||||
allowed_domains:
|
||||
- "unkin.net"
|
||||
- "unkin.local"
|
||||
allow_subdomains: true
|
||||
allow_glob_domains: false
|
||||
allow_bare_domains: true
|
||||
enforce_hostnames: false
|
||||
allow_any_name: false
|
||||
max_ttl: 31536000 # 8760h in seconds
|
||||
key_bits: 2048
|
||||
country: []
|
||||
use_csr_common_name: true
|
||||
use_csr_sans: true
|
||||
@@ -0,0 +1,4 @@
|
||||
description: "SSH CA Engine"
|
||||
max_lease_ttl_seconds: 315360000 # 87600 * 3600
|
||||
generate_signing_key: true
|
||||
key_type: ssh-rsa
|
||||
@@ -0,0 +1,8 @@
|
||||
key_type: ca
|
||||
algorithm_signer: rsa-sha2-256
|
||||
ttl: 315360000 # 87600 * 3600
|
||||
allow_host_certificates: true
|
||||
allow_user_certificates: false
|
||||
allowed_domains: "main.unkin.net,consul"
|
||||
allow_subdomains: true
|
||||
allow_bare_domains: false
|
||||
@@ -0,0 +1,3 @@
|
||||
description: "Transit Engine"
|
||||
default_lease_ttl_seconds: 3600
|
||||
max_lease_ttl_seconds: 86400
|
||||
@@ -0,0 +1,5 @@
|
||||
type: aes256-gcm96
|
||||
deletion_allowed: false
|
||||
derived: false
|
||||
exportable: false
|
||||
allow_plaintext_backup: false
|
||||
@@ -0,0 +1,80 @@
|
||||
include "root" {
|
||||
path = find_in_parent_folders("root.hcl")
|
||||
expose = true
|
||||
}
|
||||
|
||||
include "config" {
|
||||
path = "${get_repo_root()}/config/config.hcl"
|
||||
expose = true
|
||||
}
|
||||
|
||||
include "policies" {
|
||||
path = "${get_repo_root()}/policies/policies.hcl"
|
||||
expose = true
|
||||
}
|
||||
|
||||
include "resources" {
|
||||
path = "${get_repo_root()}/resources/resources.hcl"
|
||||
expose = true
|
||||
}
|
||||
|
||||
locals {
|
||||
# Extract country and region from path
|
||||
path_parts = split("/", dirname(get_terragrunt_dir()))
|
||||
country = basename(dirname(get_terragrunt_dir())) # "au"
|
||||
region = basename(get_terragrunt_dir()) # "syd1"
|
||||
|
||||
# Include configuration from config.hcl
|
||||
config = include.config.locals.config
|
||||
|
||||
# Include policies from policies.hcl
|
||||
policies = include.policies.locals
|
||||
|
||||
# Include resources from resources.hcl
|
||||
resources = include.resources.locals
|
||||
|
||||
# Create sanitized backend name mapping for Consul providers
|
||||
# Provider aliases can't contain slashes, so replace them with underscores
|
||||
consul_backend_aliases = {
|
||||
for backend_name, _ in local.config.consul_secret_backend :
|
||||
backend_name => replace(backend_name, "/", "_")
|
||||
}
|
||||
}
|
||||
|
||||
terraform {
|
||||
source = "../../../modules/vault_cluster"
|
||||
}
|
||||
|
||||
inputs = {
|
||||
country = local.country
|
||||
region = local.region
|
||||
|
||||
# Pass configuration maps to vault_cluster module
|
||||
auth_approle_backend = local.config.auth_approle_backend
|
||||
auth_approle_role = local.config.auth_approle_role
|
||||
auth_ldap_backend = local.config.auth_ldap_backend
|
||||
auth_ldap_group = local.config.auth_ldap_group
|
||||
auth_kubernetes_backend = local.config.auth_kubernetes_backend
|
||||
auth_kubernetes_role = local.config.auth_kubernetes_role
|
||||
kv_secret_backend = local.config.kv_secret_backend
|
||||
transit_secret_backend = local.config.transit_secret_backend
|
||||
transit_secret_backend_key = local.config.transit_secret_backend_key
|
||||
ssh_secret_backend = local.config.ssh_secret_backend
|
||||
ssh_secret_backend_role = local.config.ssh_secret_backend_role
|
||||
pki_secret_backend = local.config.pki_secret_backend
|
||||
pki_secret_backend_role = local.config.pki_secret_backend_role
|
||||
consul_secret_backend = local.config.consul_secret_backend
|
||||
consul_secret_backend_role = local.config.consul_secret_backend_role
|
||||
kubernetes_secret_backend = local.config.kubernetes_secret_backend
|
||||
kubernetes_secret_backend_role = local.config.kubernetes_secret_backend_role
|
||||
pki_mount_only = local.config.pki_mount_only
|
||||
litellm_secret_backend = local.config.litellm_secret_backend
|
||||
litellm_secret_backend_role = local.config.litellm_secret_backend_role
|
||||
|
||||
# Pass policy maps to vault_cluster module
|
||||
policy_auth_map = local.policies.policy_auth_map
|
||||
policy_rules_map = local.policies.policy_rules_map
|
||||
|
||||
# Pass sanitized consul backend aliases for provider configuration
|
||||
consul_backend_aliases = local.consul_backend_aliases
|
||||
}
|
||||
@@ -0,0 +1,45 @@
|
||||
# Generate root backend.tf
|
||||
generate "backend" {
|
||||
path = "backend.tf"
|
||||
if_exists = "overwrite"
|
||||
contents = <<EOF
|
||||
locals {
|
||||
vault_addr = "https://vault.service.consul:8200"
|
||||
}
|
||||
|
||||
provider "vault" {
|
||||
address = local.vault_addr
|
||||
}
|
||||
|
||||
# The LiteLLM secrets engine is managed through its own provider, which talks to
|
||||
# the same Vault server. Token falls back to the VAULT_TOKEN environment variable.
|
||||
provider "litellm" {
|
||||
address = local.vault_addr
|
||||
}
|
||||
|
||||
terraform {
|
||||
backend "consul" {
|
||||
address = "https://consul.service.consul"
|
||||
path = "infra/terraform/vault/${path_relative_to_include()}/state"
|
||||
scheme = "https"
|
||||
lock = true
|
||||
ca_file = "/etc/pki/tls/certs/ca-bundle.crt"
|
||||
}
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
vault = {
|
||||
source = "hashicorp/vault"
|
||||
version = "5.6.0"
|
||||
}
|
||||
consul = {
|
||||
source = "hashicorp/consul"
|
||||
version = "2.23.0"
|
||||
}
|
||||
litellm = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/litellmvaultsecret"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
EOF
|
||||
}
|
||||
@@ -0,0 +1,11 @@
|
||||
rule "terraform_required_providers" {
|
||||
enabled = false
|
||||
}
|
||||
|
||||
rule "terraform_required_version" {
|
||||
enabled = false
|
||||
}
|
||||
|
||||
rule "terraform_unused_declarations" {
|
||||
enabled = false
|
||||
}
|
||||
@@ -0,0 +1,367 @@
|
||||
module "auth_approle_backend" {
|
||||
source = "./modules/auth_approle_backend"
|
||||
|
||||
for_each = var.auth_approle_backend
|
||||
|
||||
path = each.key
|
||||
listing_visibility = each.value.listing_visibility
|
||||
default_lease_ttl = each.value.default_lease_ttl
|
||||
max_lease_ttl = each.value.max_lease_ttl
|
||||
}
|
||||
|
||||
module "auth_approle_role" {
|
||||
source = "./modules/auth_approle_role"
|
||||
|
||||
for_each = var.auth_approle_role
|
||||
|
||||
country = var.country
|
||||
region = var.region
|
||||
approle_name = each.value.approle_name
|
||||
mount_path = each.value.mount_path
|
||||
token_policies = var.policy_auth_map[each.value.mount_path][each.value.approle_name]
|
||||
token_ttl = each.value.token_ttl
|
||||
token_max_ttl = each.value.token_max_ttl
|
||||
bind_secret_id = each.value.bind_secret_id
|
||||
secret_id_ttl = each.value.secret_id_ttl
|
||||
token_bound_cidrs = each.value.token_bound_cidrs
|
||||
alias_metadata = each.value.alias_metadata
|
||||
use_deterministic_role_id = each.value.use_deterministic_role_id
|
||||
|
||||
depends_on = [module.auth_approle_backend]
|
||||
}
|
||||
|
||||
module "auth_ldap_backend" {
|
||||
source = "./modules/auth_ldap_backend"
|
||||
|
||||
for_each = var.auth_ldap_backend
|
||||
|
||||
country = var.country
|
||||
region = var.region
|
||||
path = each.key
|
||||
userdn = each.value.userdn
|
||||
userattr = each.value.userattr
|
||||
upndomain = each.value.upndomain
|
||||
discoverdn = each.value.discoverdn
|
||||
groupdn = each.value.groupdn
|
||||
groupfilter = each.value.groupfilter
|
||||
groupattr = each.value.groupattr
|
||||
alias_metadata = each.value.alias_metadata
|
||||
username_as_alias = each.value.username_as_alias
|
||||
listing_visibility = each.value.listing_visibility
|
||||
default_lease_ttl = each.value.default_lease_ttl
|
||||
max_lease_ttl = each.value.max_lease_ttl
|
||||
}
|
||||
|
||||
module "auth_ldap_group" {
|
||||
source = "./modules/auth_ldap_group"
|
||||
|
||||
for_each = var.auth_ldap_group
|
||||
|
||||
groupname = each.value.groupname
|
||||
backend = each.value.backend
|
||||
policies = var.policy_auth_map[each.value.backend][each.value.groupname]
|
||||
|
||||
depends_on = [module.auth_ldap_backend]
|
||||
}
|
||||
|
||||
module "auth_kubernetes_backend" {
|
||||
source = "./modules/auth_kubernetes_backend"
|
||||
|
||||
for_each = var.auth_kubernetes_backend
|
||||
|
||||
country = var.country
|
||||
region = var.region
|
||||
path = each.key
|
||||
kubernetes_host = each.value.kubernetes_host
|
||||
disable_iss_validation = each.value.disable_iss_validation
|
||||
use_annotations_as_alias_metadata = each.value.use_annotations_as_alias_metadata
|
||||
listing_visibility = each.value.listing_visibility
|
||||
default_lease_ttl = each.value.default_lease_ttl
|
||||
max_lease_ttl = each.value.max_lease_ttl
|
||||
}
|
||||
|
||||
module "auth_kubernetes_role" {
|
||||
source = "./modules/auth_kubernetes_role"
|
||||
|
||||
for_each = var.auth_kubernetes_role
|
||||
|
||||
role_name = each.value.role_name
|
||||
backend = each.value.backend
|
||||
bound_service_account_names = each.value.bound_service_account_names
|
||||
bound_service_account_namespaces = each.value.bound_service_account_namespaces
|
||||
token_ttl = each.value.token_ttl
|
||||
token_max_ttl = each.value.token_max_ttl
|
||||
token_policies = var.policy_auth_map[each.value.backend][each.value.role_name]
|
||||
audience = each.value.audience
|
||||
|
||||
depends_on = [module.auth_kubernetes_backend]
|
||||
}
|
||||
|
||||
module "kv_secret_backend" {
|
||||
source = "./modules/kv_secret_backend"
|
||||
|
||||
for_each = var.kv_secret_backend
|
||||
|
||||
path = each.key
|
||||
type = each.value.type
|
||||
description = each.value.description
|
||||
kv_version = each.value.version
|
||||
max_versions = each.value.max_versions
|
||||
}
|
||||
|
||||
module "transit_secret_backend" {
|
||||
source = "./modules/transit_secret_backend"
|
||||
|
||||
for_each = var.transit_secret_backend
|
||||
|
||||
path = each.key
|
||||
description = each.value.description
|
||||
default_lease_ttl_seconds = each.value.default_lease_ttl_seconds
|
||||
max_lease_ttl_seconds = each.value.max_lease_ttl_seconds
|
||||
}
|
||||
|
||||
module "transit_secret_backend_key" {
|
||||
source = "./modules/transit_secret_backend_key"
|
||||
|
||||
for_each = var.transit_secret_backend_key
|
||||
|
||||
name = each.value.name
|
||||
backend = each.value.backend
|
||||
type = each.value.type
|
||||
deletion_allowed = each.value.deletion_allowed
|
||||
derived = each.value.derived
|
||||
exportable = each.value.exportable
|
||||
allow_plaintext_backup = each.value.allow_plaintext_backup
|
||||
auto_rotate_period = each.value.auto_rotate_period
|
||||
|
||||
depends_on = [module.transit_secret_backend]
|
||||
}
|
||||
|
||||
module "ssh_secret_backend" {
|
||||
source = "./modules/ssh_secret_backend"
|
||||
|
||||
for_each = var.ssh_secret_backend
|
||||
|
||||
path = each.key
|
||||
description = each.value.description
|
||||
max_lease_ttl_seconds = each.value.max_lease_ttl_seconds
|
||||
generate_signing_key = each.value.generate_signing_key
|
||||
key_type = each.value.key_type
|
||||
}
|
||||
|
||||
module "ssh_secret_backend_role" {
|
||||
source = "./modules/ssh_secret_backend_role"
|
||||
|
||||
for_each = var.ssh_secret_backend_role
|
||||
|
||||
name = each.value.name
|
||||
backend = each.value.backend
|
||||
key_type = each.value.key_type
|
||||
algorithm_signer = each.value.algorithm_signer
|
||||
ttl = each.value.ttl
|
||||
allow_host_certificates = each.value.allow_host_certificates
|
||||
allow_user_certificates = each.value.allow_user_certificates
|
||||
allowed_domains = each.value.allowed_domains
|
||||
allow_subdomains = each.value.allow_subdomains
|
||||
allow_bare_domains = each.value.allow_bare_domains
|
||||
|
||||
depends_on = [module.ssh_secret_backend]
|
||||
}
|
||||
|
||||
module "pki_secret_backend" {
|
||||
source = "./modules/pki_secret_backend"
|
||||
|
||||
for_each = var.pki_secret_backend
|
||||
|
||||
path = each.key
|
||||
description = each.value.description
|
||||
max_lease_ttl_seconds = each.value.max_lease_ttl_seconds
|
||||
common_name = each.value.common_name
|
||||
issuer_name = each.value.issuer_name
|
||||
ttl = each.value.ttl
|
||||
format = each.value.format
|
||||
issuing_certificates = each.value.issuing_certificates
|
||||
crl_distribution_points = each.value.crl_distribution_points
|
||||
ocsp_servers = each.value.ocsp_servers
|
||||
enable_templating = each.value.enable_templating
|
||||
default_follows_latest_issuer = each.value.default_follows_latest_issuer
|
||||
crl_expiry = each.value.crl_expiry
|
||||
crl_disable = each.value.crl_disable
|
||||
ocsp_disable = each.value.ocsp_disable
|
||||
auto_rebuild = each.value.auto_rebuild
|
||||
enable_delta = each.value.enable_delta
|
||||
delta_rebuild_interval = each.value.delta_rebuild_interval
|
||||
}
|
||||
|
||||
module "pki_secret_backend_role" {
|
||||
source = "./modules/pki_secret_backend_role"
|
||||
|
||||
for_each = var.pki_secret_backend_role
|
||||
|
||||
name = each.value.name
|
||||
backend = each.value.backend
|
||||
allow_ip_sans = each.value.allow_ip_sans
|
||||
allowed_domains = each.value.allowed_domains
|
||||
allow_subdomains = each.value.allow_subdomains
|
||||
allow_glob_domains = each.value.allow_glob_domains
|
||||
allow_bare_domains = each.value.allow_bare_domains
|
||||
enforce_hostnames = each.value.enforce_hostnames
|
||||
allow_any_name = each.value.allow_any_name
|
||||
max_ttl = each.value.max_ttl
|
||||
key_bits = each.value.key_bits
|
||||
country = each.value.country
|
||||
use_csr_common_name = each.value.use_csr_common_name
|
||||
use_csr_sans = each.value.use_csr_sans
|
||||
|
||||
depends_on = [module.pki_secret_backend]
|
||||
}
|
||||
|
||||
module "consul_secret_backend" {
|
||||
source = "./modules/consul_secret_backend"
|
||||
|
||||
for_each = var.consul_secret_backend
|
||||
|
||||
country = var.country
|
||||
region = var.region
|
||||
path = each.key
|
||||
description = each.value.description
|
||||
address = each.value.address
|
||||
bootstrap = each.value.bootstrap
|
||||
scheme = each.value.scheme
|
||||
ca_cert = each.value.ca_cert
|
||||
client_cert = each.value.client_cert
|
||||
client_key = each.value.client_key
|
||||
default_lease_ttl_seconds = each.value.default_lease_ttl_seconds
|
||||
max_lease_ttl_seconds = each.value.max_lease_ttl_seconds
|
||||
}
|
||||
|
||||
# Create data sources for consul backend tokens
|
||||
data "vault_kv_secret_v2" "consul_backend_configs" {
|
||||
for_each = {
|
||||
for k, v in var.consul_secret_backend : k => v
|
||||
if !v.bootstrap
|
||||
}
|
||||
|
||||
mount = "kv"
|
||||
name = "service/vault/${var.country}/${var.region}/secret_backend/${each.key}"
|
||||
}
|
||||
|
||||
# Create Consul ACL management module
|
||||
module "consul_acl_management" {
|
||||
source = "./modules/consul_acl_management"
|
||||
|
||||
country = var.country
|
||||
region = var.region
|
||||
consul_backends = var.consul_secret_backend
|
||||
consul_roles = var.consul_secret_backend_role
|
||||
consul_backend_aliases = var.consul_backend_aliases
|
||||
}
|
||||
|
||||
# Create consul secret backend roles (Vault resources only)
|
||||
module "consul_secret_backend_role" {
|
||||
source = "./modules/consul_secret_backend_role"
|
||||
|
||||
for_each = var.consul_secret_backend_role
|
||||
|
||||
name = each.value.name
|
||||
backend = each.value.backend
|
||||
ttl = each.value.ttl
|
||||
max_ttl = each.value.max_ttl
|
||||
local = each.value.local
|
||||
|
||||
depends_on = [module.consul_secret_backend, module.consul_acl_management]
|
||||
}
|
||||
|
||||
module "kubernetes_secret_backend" {
|
||||
source = "./modules/kubernetes_secret_backend"
|
||||
|
||||
for_each = var.kubernetes_secret_backend
|
||||
|
||||
country = var.country
|
||||
region = var.region
|
||||
path = each.key
|
||||
description = each.value.description
|
||||
default_lease_ttl_seconds = each.value.default_lease_ttl_seconds
|
||||
max_lease_ttl_seconds = each.value.max_lease_ttl_seconds
|
||||
kubernetes_host = each.value.kubernetes_host
|
||||
disable_local_ca_jwt = each.value.disable_local_ca_jwt
|
||||
}
|
||||
|
||||
module "kubernetes_secret_backend_role" {
|
||||
source = "./modules/kubernetes_secret_backend_role"
|
||||
|
||||
for_each = var.kubernetes_secret_backend_role
|
||||
|
||||
country = var.country
|
||||
region = var.region
|
||||
name = each.value.name
|
||||
backend = each.value.backend
|
||||
allowed_kubernetes_namespaces = each.value.allowed_kubernetes_namespaces
|
||||
kubernetes_role_type = each.value.kubernetes_role_type
|
||||
extra_labels = each.value.extra_labels
|
||||
|
||||
depends_on = [module.kubernetes_secret_backend]
|
||||
}
|
||||
|
||||
module "litellm_secret_backend" {
|
||||
source = "./modules/litellm_secret_backend"
|
||||
|
||||
for_each = var.litellm_secret_backend
|
||||
|
||||
country = var.country
|
||||
region = var.region
|
||||
path = each.key
|
||||
plugin = each.value.plugin
|
||||
description = each.value.description
|
||||
base_url = each.value.base_url
|
||||
request_timeout_seconds = each.value.request_timeout_seconds
|
||||
}
|
||||
|
||||
module "litellm_secret_backend_role" {
|
||||
source = "./modules/litellm_secret_backend_role"
|
||||
|
||||
for_each = var.litellm_secret_backend_role
|
||||
|
||||
name = each.value.name
|
||||
backend = each.value.backend
|
||||
models = each.value.models
|
||||
max_budget = each.value.max_budget
|
||||
key_alias_prefix = each.value.key_alias_prefix
|
||||
ttl = each.value.ttl
|
||||
max_ttl = each.value.max_ttl
|
||||
metadata = each.value.metadata
|
||||
|
||||
depends_on = [module.litellm_secret_backend]
|
||||
}
|
||||
|
||||
module "vault_policy" {
|
||||
source = "./modules/vault_policy"
|
||||
|
||||
for_each = var.policy_rules_map
|
||||
|
||||
policy_name = each.key
|
||||
policy_rules = each.value
|
||||
}
|
||||
|
||||
module "pki_mount_only" {
|
||||
source = "./modules/pki_mount_only"
|
||||
|
||||
for_each = var.pki_mount_only
|
||||
|
||||
path = each.key
|
||||
description = each.value.description
|
||||
max_lease_ttl_seconds = each.value.max_lease_ttl_seconds
|
||||
issuing_certificates = each.value.issuing_certificates
|
||||
crl_distribution_points = each.value.crl_distribution_points
|
||||
ocsp_servers = each.value.ocsp_servers
|
||||
enable_templating = each.value.enable_templating
|
||||
default_issuer_ref = each.value.default_issuer_ref
|
||||
default_follows_latest_issuer = each.value.default_follows_latest_issuer
|
||||
crl_expiry = each.value.crl_expiry
|
||||
crl_disable = each.value.crl_disable
|
||||
ocsp_disable = each.value.ocsp_disable
|
||||
auto_rebuild = each.value.auto_rebuild
|
||||
enable_delta = each.value.enable_delta
|
||||
delta_rebuild_interval = each.value.delta_rebuild_interval
|
||||
}
|
||||
|
||||
@@ -0,0 +1,11 @@
|
||||
|
||||
resource "vault_auth_backend" "approle" {
|
||||
type = "approle"
|
||||
path = var.path
|
||||
|
||||
tune {
|
||||
default_lease_ttl = var.default_lease_ttl
|
||||
max_lease_ttl = var.max_lease_ttl
|
||||
listing_visibility = var.listing_visibility
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,4 @@
|
||||
output "backend" {
|
||||
description = "The created auth backend"
|
||||
value = vault_auth_backend.approle
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
vault = {
|
||||
source = "hashicorp/vault"
|
||||
version = "5.6.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,27 @@
|
||||
variable "path" {
|
||||
description = "Mount path of the AppRole auth backend"
|
||||
type = string
|
||||
default = "approle"
|
||||
}
|
||||
|
||||
variable "listing_visibility" {
|
||||
description = "Specifies whether to show this mount in the UI-specific listing endpoint. Valid values are 'unauth' or 'hidden'"
|
||||
type = string
|
||||
default = null
|
||||
validation {
|
||||
condition = var.listing_visibility == null || contains(["unauth", "hidden"], var.listing_visibility)
|
||||
error_message = "listing_visibility must be either 'unauth' or 'hidden'."
|
||||
}
|
||||
}
|
||||
|
||||
variable "default_lease_ttl" {
|
||||
description = "Specifies the default time-to-live. If set, this overrides the global default. Must be a valid duration string"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "max_lease_ttl" {
|
||||
description = "Specifies the maximum time-to-live. If set, this overrides the global default. Must be a valid duration string"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
@@ -0,0 +1,36 @@
|
||||
|
||||
# Expected keys in KV secret for salt: salt
|
||||
data "vault_kv_secret_v2" "salt_config" {
|
||||
mount = "kv"
|
||||
name = "service/vault/${var.country}/${var.region}/auth_backend/${var.mount_path}"
|
||||
}
|
||||
|
||||
# Expected keys in KV secret for role_id: role_id (when use_deterministic_role_id = false)
|
||||
data "vault_kv_secret_v2" "role_config" {
|
||||
count = var.use_deterministic_role_id ? 0 : 1
|
||||
|
||||
mount = "kv"
|
||||
name = "service/vault/${var.country}/${var.region}/auth_approle_role/${var.mount_path}/${var.approle_name}"
|
||||
}
|
||||
|
||||
locals {
|
||||
salt = data.vault_kv_secret_v2.salt_config.data["salt"]
|
||||
role_id_input = "${local.salt}-${var.approle_name}-${var.mount_path}"
|
||||
deterministic_role_id = uuidv5("dns", local.role_id_input)
|
||||
|
||||
# Use deterministic role-id by default, or read from KV if specified
|
||||
role_id = var.use_deterministic_role_id ? local.deterministic_role_id : data.vault_kv_secret_v2.role_config[0].data["role_id"]
|
||||
}
|
||||
|
||||
resource "vault_approle_auth_backend_role" "role" {
|
||||
backend = var.mount_path
|
||||
role_name = var.approle_name
|
||||
role_id = local.role_id
|
||||
token_policies = var.token_policies
|
||||
token_ttl = var.token_ttl
|
||||
token_max_ttl = var.token_max_ttl
|
||||
bind_secret_id = var.bind_secret_id
|
||||
secret_id_ttl = var.secret_id_ttl
|
||||
token_bound_cidrs = var.token_bound_cidrs
|
||||
alias_metadata = var.alias_metadata
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
vault = {
|
||||
source = "hashicorp/vault"
|
||||
version = "5.6.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,68 @@
|
||||
variable "country" {
|
||||
description = "Country identifier"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "region" {
|
||||
description = "Region identifier"
|
||||
type = string
|
||||
}
|
||||
|
||||
|
||||
variable "approle_name" {
|
||||
description = "Name of the AppRole role"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "mount_path" {
|
||||
description = "Mount path of the AppRole auth backend"
|
||||
type = string
|
||||
default = "approle"
|
||||
}
|
||||
|
||||
variable "token_policies" {
|
||||
description = "List of policies to assign to the role (passed from policy_auth_map)"
|
||||
type = list(string)
|
||||
}
|
||||
|
||||
variable "token_ttl" {
|
||||
description = "The TTL period of tokens issued using this role"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "token_max_ttl" {
|
||||
description = "The maximum TTL period of tokens issued using this role"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "bind_secret_id" {
|
||||
description = "Whether or not to require secret_id to be presented when logging in using this AppRole"
|
||||
type = bool
|
||||
default = false
|
||||
}
|
||||
|
||||
variable "secret_id_ttl" {
|
||||
description = "The TTL period of SecretIDs generated against this AppRole"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "token_bound_cidrs" {
|
||||
description = "List of CIDR blocks that can authenticate using this role"
|
||||
type = list(string)
|
||||
default = []
|
||||
}
|
||||
|
||||
variable "alias_metadata" {
|
||||
description = "The metadata to be tied to generated entity alias. This should be a list or map containing the metadata in key value pairs"
|
||||
type = map(string)
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "use_deterministic_role_id" {
|
||||
description = "Whether to use deterministic role-id generation (true) or read pre-generated role-id from KV (false)"
|
||||
type = bool
|
||||
default = true
|
||||
}
|
||||
@@ -0,0 +1,25 @@
|
||||
# Expected keys in KV secret: kubernetes_ca_cert, token_reviewer_jwt
|
||||
data "vault_kv_secret_v2" "auth_backend_config" {
|
||||
mount = "kv"
|
||||
name = "service/vault/${var.country}/${var.region}/auth_backend/${var.path}"
|
||||
}
|
||||
|
||||
resource "vault_auth_backend" "kubernetes" {
|
||||
type = "kubernetes"
|
||||
path = var.path
|
||||
|
||||
tune {
|
||||
default_lease_ttl = var.default_lease_ttl
|
||||
max_lease_ttl = var.max_lease_ttl
|
||||
listing_visibility = var.listing_visibility
|
||||
}
|
||||
}
|
||||
|
||||
resource "vault_kubernetes_auth_backend_config" "config" {
|
||||
backend = vault_auth_backend.kubernetes.path
|
||||
kubernetes_host = var.kubernetes_host
|
||||
kubernetes_ca_cert = data.vault_kv_secret_v2.auth_backend_config.data["kubernetes_ca_cert"]
|
||||
token_reviewer_jwt = data.vault_kv_secret_v2.auth_backend_config.data["token_reviewer_jwt"]
|
||||
disable_iss_validation = var.disable_iss_validation
|
||||
use_annotations_as_alias_metadata = var.use_annotations_as_alias_metadata
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
vault = {
|
||||
source = "hashicorp/vault"
|
||||
version = "5.6.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,54 @@
|
||||
variable "country" {
|
||||
description = "Country identifier"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "region" {
|
||||
description = "Region identifier"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "path" {
|
||||
description = "Mount path of the Kubernetes auth backend"
|
||||
type = string
|
||||
default = "kubernetes"
|
||||
}
|
||||
|
||||
variable "disable_iss_validation" {
|
||||
description = "Disable JWT issuer validation"
|
||||
type = bool
|
||||
default = true
|
||||
}
|
||||
|
||||
variable "use_annotations_as_alias_metadata" {
|
||||
description = "Use annotations as alias metadata"
|
||||
type = bool
|
||||
default = true
|
||||
}
|
||||
|
||||
variable "listing_visibility" {
|
||||
description = "Specifies whether to show this mount in the UI-specific listing endpoint. Valid values are 'unauth' or 'hidden'"
|
||||
type = string
|
||||
default = null
|
||||
validation {
|
||||
condition = var.listing_visibility == null || contains(["unauth", "hidden"], var.listing_visibility)
|
||||
error_message = "listing_visibility must be either 'unauth' or 'hidden'."
|
||||
}
|
||||
}
|
||||
|
||||
variable "default_lease_ttl" {
|
||||
description = "Specifies the default time-to-live. If set, this overrides the global default. Must be a valid duration string"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "max_lease_ttl" {
|
||||
description = "Specifies the maximum time-to-live. If set, this overrides the global default. Must be a valid duration string"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "kubernetes_host" {
|
||||
description = "Host must be a host string, a host:port pair, or a URL to the base of the Kubernetes API server"
|
||||
type = string
|
||||
}
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user