unkinben
ecee4b4432
fix: grant vault deployer access to manage the litellm engine
...
Applying the litellm mount failed with 403 permission denied on
PUT litellm/config: the deployer identity (tf_vault approle /
woodpecker_terraform_vault k8s role) could enable the mount via
sys/mounts/admin but had no policy covering the engine's own data paths.
Add a litellm/admin policy granting create/read/update/delete on
litellm/config and litellm/roles/*, assigned to the same auth roles as the
other secret-engine admin policies.
2026-07-07 00:23:20 +10:00
unkinben
9e2c21131f
feat: manage litellm secrets engine via terraform-provider-litellmvaultsecret
...
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
The vault-plugin-secrets-litellm engine mints LiteLLM virtual keys and is
now registered in Vault, but nothing declared its mount/config or roles in
this repo. Wire in the companion litellm provider so the mount is managed
as code alongside the other secret backends.
- Add litellm_secret_backend module: mounts the engine and writes its
config (base_url, request_timeout_seconds); reads master_key from KV
- Add litellm_secret_backend_role module: manages roles (models,
max_budget, key_alias_prefix, ttl/max_ttl seconds, metadata)
- Register both modules in vault_cluster main.tf and variables.tf
- Discover litellm_secret_backend[_role] YAML in config.hcl and pass them
through terragrunt inputs
- Declare the litellm provider (litellmvaultsecret) and
a provider block in the generated root backend.tf
- Add example config for the litellm mount and a sample role
2026-07-07 00:15:07 +10:00
unkinben
bbde79d2a6
policies: let terraform-authentik read its provider API token ( #82 )
...
ci/woodpecker/push/apply Pipeline was successful
## Why
terraform-authentik's provider needs an Authentik API token (`TF_VAR_authentik_token`), now sourced from Vault at `kv/service/terraform/authentik` (Makefile wiring in terraform-authentik #2 ). The CI role needs read access to that path.
## Change
Extend `policies/kv/service/terraform/authentik.yaml` to also grant read on `kv/data/service/terraform/authentik` for the `terraform_authentik` approle + `woodpecker_terraform_authentik` k8s role.
Reviewed-on: #82
Co-authored-by: Ben Vincent <ben@unkin.net >
Co-committed-by: Ben Vincent <ben@unkin.net >
2026-07-06 23:41:03 +10:00
unkinben
f2c54888de
policies: let terraform-authentik read oauth client secrets from kv ( #81 )
...
ci/woodpecker/push/apply Pipeline was successful
## Why
terraform-authentik now reads OAuth2 client secrets from Vault (`data.vault_kv_secret_v2`) rather than committing them (terraform-authentik #2 ). But the `terraform_authentik` approle / `woodpecker_terraform_authentik` k8s role only had the consul-creds policy, so `plan` fails with permission denied on the grafana oauth path.
## Change
Add `policies/kv/service/terraform/authentik.yaml` granting read on `kv/data/kubernetes/namespace/+/default/oauth-credentials` for both the approle and the woodpecker k8s role.
Reviewed-on: #81
Co-authored-by: Ben Vincent <ben@unkin.net >
Co-committed-by: Ben Vincent <ben@unkin.net >
2026-07-06 23:05:20 +10:00
unkinben
36d7afbb65
feat: add vault/consul config for media terraform repos ( #79 )
...
ci/woodpecker/push/apply Pipeline was successful
Add Kubernetes auth roles, AppRole configs, Consul secret backend roles, Consul ACL policies, and Vault kv read policies for terraform-sonarr, terraform-radarr, and terraform-prowlarr.
Reviewed-on: #79
Co-authored-by: Ben Vincent <ben@unkin.net >
Co-committed-by: Ben Vincent <ben@unkin.net >
2026-06-28 22:03:25 +10:00
unkinben
c33dcdc447
Add auth and state access for terraform-authentik ( #78 )
...
ci/woodpecker/push/apply Pipeline was successful
## Summary
- K8s auth role for Woodpecker CI (`terraform-authentik` SA in `woodpecker` namespace)
- AppRole for local terraform runs
- Consul secret backend role (`terraform-authentik`, TTL 120/300)
- Consul ACL policy for `infra/terraform/authentik/` key prefix
- Vault policy granting both auth methods access to Consul creds
Reviewed-on: #78
Co-authored-by: Ben Vincent <ben@unkin.net >
Co-committed-by: Ben Vincent <ben@unkin.net >
2026-06-28 01:17:51 +10:00
benvin
be9bd96cf3
feat: enable consul state store for artifactapi ( #77 )
...
ci/woodpecker/push/apply Pipeline was successful
enable the terraform-artifactapi system to manage its state in consul
using dynamic credentials from kubernetes ci jobs in woodpecker
---------
Co-authored-by: Ben Vincent <ben@unkin.net >
Reviewed-on: #77
2026-06-17 21:42:25 +10:00
unkinben
bb5f6922fa
feat: add vault policy for terraform-git webhook secrets ( #75 )
...
ci/woodpecker/push/apply Pipeline was successful
## Summary
- Add read policy for kv/data/service/gitea/webhook/* path
- Assigned to terraform_git approle and woodpecker_terraform_git k8s auth role
- Webhook URLs are stored in Vault KV and read at plan/apply time
## Test plan
- [ ] Verify terragrunt plan succeeds for terraform-git after merge
Reviewed-on: #75
Co-authored-by: Ben Vincent <ben@unkin.net >
Co-committed-by: Ben Vincent <ben@unkin.net >
2026-06-08 22:56:30 +10:00
benvin
346cf9fa43
feat: manage gitadmin token ( #74 )
...
ci/woodpecker/push/apply Pipeline was successful
- add approle for terraform-git
- add policy to read gitadmin token
- update access to the terraform-git consul token
---------
Co-authored-by: Ben Vincent <ben@unkin.net >
Reviewed-on: #74
2026-06-08 15:17:58 +10:00
unkinben
1288057b81
feat: add vault and consul roles for terraform-git ( #73 )
...
ci/woodpecker/push/apply Pipeline was successful
## Summary
- Add K8s auth role woodpecker_terraform_git for CI pipeline authentication
- Add consul secret backend role terraform-git for consul state storage tokens
- Add consul ACL policy granting write access to infra/terraform/git/ key prefix
- Add vault policy for reading consul creds at consul_root/au/syd1/creds/terraform-git
## Test plan
- [ ] Verify terragrunt plan succeeds
- [ ] Verify consul ACL policy is created correctly
- [ ] Verify K8s auth role can authenticate from woodpecker namespace
Reviewed-on: #73
Co-authored-by: Ben Vincent <ben@unkin.net >
Co-committed-by: Ben Vincent <ben@unkin.net >
2026-06-07 20:36:35 +10:00
unkinben
3876fa818d
chore: bump almalinux9 image tags ( #72 )
...
ci/woodpecker/push/apply Pipeline was successful
Bump almalinux9 image tags to 20260606
Reviewed-on: #72
Co-authored-by: Ben Vincent <ben@unkin.net >
Co-committed-by: Ben Vincent <ben@unkin.net >
2026-06-07 00:35:30 +10:00
unkinben
a548bf1cb1
fix: apply requires plan ( #71 )
...
ci/woodpecker/push/apply Pipeline was successful
- ensure make plan runs before make apply when deploying
Reviewed-on: #71
2026-05-22 00:03:08 +10:00
unkinben
93ba86baf3
feat: add apply workflow ( #70 )
...
ci/woodpecker/push/apply Pipeline was successful
Reviewed-on: #70
2026-05-21 23:57:25 +10:00
unkinben
098830c10b
Merge pull request 'feat: add plan workflow' ( #69 ) from benvin/make-plan-buildwq into master
...
Reviewed-on: #69
2026-05-21 23:54:07 +10:00
unkinben
9cbac6d3ef
feat: add plan workflow
...
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/plan Pipeline was successful
- update makefile to enable kubernetes auth or roleid auth
- add plan workflow
- update all policies to allow the terraform-vault kubernetes role
2026-05-21 23:52:30 +10:00
unkinben
73aaaaeb99
Merge pull request 'chore: enable access to gateway.networking.k8s.io' ( #68 ) from benvin/gatewayapi into master
...
Reviewed-on: #68
2026-05-21 22:42:28 +10:00
unkinben
7c60a5fd53
chore: enable access to gateway.networking.k8s.io
ci/woodpecker/pr/pre-commit Pipeline was successful
2026-05-21 22:39:57 +10:00
unkinben
27f12f183e
Merge pull request 'chore: change to specific ci image' ( #67 ) from benvin/ci_image into master
...
Reviewed-on: #67
2026-03-09 01:16:59 +11:00
unkinben
c61434b692
chore: change to specific ci image
...
ci/woodpecker/pr/pre-commit Pipeline was successful
- almalinux9-opentofu image contains all required tools
2026-03-09 01:14:41 +11:00
unkinben
172ceac2fc
Merge pull request 'feat: add templated policies for kubernetes' ( #66 ) from benvin/kubernetes_structured_paths into master
...
Reviewed-on: #66
2026-03-08 12:57:58 +11:00
unkinben
48a4fd0dd1
feat: add templated policies for kubernetes
...
ci/woodpecker/pr/pre-commit Pipeline was successful
- add default kubernetes auth role
- add templated access kv/kubernetes/*
2026-03-08 12:48:08 +11:00
unkinben
4dc09547ef
Merge pull request 'fix: update audience for rpmbuilder' ( #65 ) from benvin/default_aud into master
...
Reviewed-on: #65
2026-03-08 12:29:43 +11:00
unkinben
546a9efe44
fix: update audience for rpmbuilder
...
ci/woodpecker/pr/pre-commit Pipeline was successful
when using using the service account jwt directly, the default audience
is the api servers url
2026-03-07 11:31:36 +11:00
unkinben
679cec4bc1
Merge pull request 'feat: add rpmbuilder k8s role' ( #64 ) from benvin/rpmbuilder-in-k8s into master
...
Reviewed-on: #64
2026-03-07 11:11:23 +11:00
unkinben
71789f9f32
feat: add rpmbuilder k8s role
...
ci/woodpecker/pr/pre-commit Pipeline was successful
- create rpmbuilder role
- enable access to gitea/github ro-tokens
- enable access to rpmbuilder role from woodpeckerci
2026-03-07 11:06:27 +11:00
unkinben
4cbcec58d3
Merge pull request 'feat: enable woodpecker access to ro tokens' ( #63 ) from benvin/woodpecker_task_access into master
...
Reviewed-on: #63
2026-03-07 10:52:38 +11:00
unkinben
9c93e185f8
feat: enable woodpecker access to ro tokens
...
ci/woodpecker/pr/pre-commit Pipeline was successful
- enable woodpecker tasks to access gitea/github read-only tokens
2026-03-07 10:49:39 +11:00
unkinben
d6c8474bd3
Merge pull request 'chore: move pgsql password to vault' ( #62 ) from benvin/artifactapi_postgrespassword into master
...
Reviewed-on: #62
2026-03-06 19:51:25 +11:00
unkinben
42351000ee
chore: move pgsql password to vault
...
ci/woodpecker/pr/pre-commit Pipeline was successful
- no more storing secrets in configmaps
2026-03-06 19:39:36 +11:00
unkinben
f7d1330c37
Merge pull request 'chore: add artifactapi k8s role' ( #61 ) from benvin/artifactapi into master
...
Reviewed-on: #61
2026-03-06 18:57:05 +11:00
unkinben
d9e07e432e
chore: add artifactapi k8s role
...
ci/woodpecker/pr/pre-commit Pipeline was successful
- enable access to read artifactapi secrets
2026-03-06 18:53:42 +11:00
unkinben
14a258de7d
Merge pull request 'chore: enable access woodpecker-agent-secret' ( #60 ) from benvin/woodpecker_agent_secret into master
...
Reviewed-on: #60
2026-03-03 23:34:32 +11:00
unkinben
be8bcc3743
chore: enable access woodpecker-agent-secret
...
ci/woodpecker/pr/pre-commit Pipeline was successful
- add policy to access woodpecker-agent-secret
2026-03-03 23:30:49 +11:00
unkinben
dc257b1bcd
Merge pull request 'feat: add pre-commit check in ci' ( #59 ) from benvin/woodpecker_integration into master
...
Reviewed-on: #59
2026-02-28 22:28:21 +11:00
unkinben
66119e5207
feat: add pre-commit check in ci
...
ci/woodpecker/pr/pre-commit Pipeline was successful
- add a ci workflow to verify pre-commit passes
- fix pre-commit errors/warnings:
- missing required_version
- missing required_providers
- fixed terraform_deprecated_interpolation
- removed terraform_unused_declarations
2026-02-28 21:42:47 +11:00
unkinben
9e6de4dc32
Merge pull request 'feat: set max token life for auth_kubernetes_role' ( #58 ) from benvin/token_max_ttl into master
...
Reviewed-on: #58
2026-02-22 22:30:18 +11:00
unkinben
7cafafd483
feat: set max token life for auth_kubernetes_role
...
found kubernetes vaultauth resources never picking up new policies,
because they would infinitely renew their token.
- set default max token length for roles to 1 day
- changed all existing role token_max_ttl to match their token_ttl
2026-02-22 22:28:21 +11:00
unkinben
c94b2af196
Merge pull request 'feat: add woodpecker secrets' ( #57 ) from benvin/woodpecker into master
...
Reviewed-on: #57
2026-02-22 22:27:50 +11:00
unkinben
dd44146d88
feat: add woodpecker secrets
...
- add secrets required to integrate woodpecker into gitea/pgsql
2026-02-22 22:27:30 +11:00
unkinben
18a62332f6
Merge pull request 'chore: enable access to openldap admin creds' ( #56 ) from benvin/ldap_admin_pass_terraform_ldap into master
...
Reviewed-on: #56
2026-02-15 20:17:35 +11:00
unkinben
8fa68e2670
chore: enable access to openldap admin creds
...
- ensure terraform_ldap can read ldap admin credentials
2026-02-15 20:16:58 +11:00
unkinben
4cad39989f
Merge pull request 'chore: add default_user_password credentials policy' ( #55 ) from benvin/openldap_default_pass into master
...
Reviewed-on: #55
2026-02-15 13:45:45 +11:00
unkinben
c825962490
chore: add default_user_password credentials policy
...
- fix the comment for ldap_admin_password
- add policy to read default_user_password
2026-02-15 13:43:02 +11:00
unkinben
51bc3fffc0
Merge pull request 'feat: add terraform-ldap service' ( #54 ) from benvin/terraform-ldap into master
...
Reviewed-on: #54
2026-02-15 13:40:32 +11:00
unkinben
dca26029c0
feat: add terraform-ldap service
...
- add consul role/policy/acls to allow terraform-ldap state management
- add approle to generate tokens for consul
2026-02-15 13:38:31 +11:00
unkinben
d398911108
Merge pull request 'fix: kubernetes auth fixes' ( #53 ) from benvin/kubernetes_fixes into master
...
Reviewed-on: #53
2026-02-15 13:08:43 +11:00
unkinben
c093d5830d
fix: kubernetes auth fixes
...
- annotations as alias metadata does not work with openbao (idempotency issue)
- set token_ttl to be 600 for all auth roles for kubernetes (min)
2026-02-15 13:06:08 +11:00
unkinben
4b176846f2
Merge pull request 'feat: add identity secrets' ( #52 ) from benvin/identity into master
...
Reviewed-on: #52
2026-02-15 13:02:01 +11:00
unkinben
90b765d713
feat: add identity secrets
...
- add kubernetes auth role for identity namespace
- add policy to access openldap bootstrap credentials
2026-02-15 13:01:06 +11:00
unkinben
3fb5a64a17
Merge pull request 'feat: add kubernetes ldap groups' ( #51 ) from benvin/kubernetes_ldap_groups into master
...
Reviewed-on: #51
2026-02-14 19:48:56 +11:00
unkinben
33a746e545
feat: add kubernetes ldap groups
...
vault's terraform approle doesnt need to access all of these kubernetes
roles, it was just added as a placeholder and access to the kubernetes
roles was via the `vault_admin` to-much-access account. this is an
effort to roll back that and make access more targeted.
- add kubernetes* ldap groups for specific cluster/role combinations
- remove tf_vault from kubernetes* roles
2026-02-14 19:46:39 +11:00
unkinben
4fe0e0de73
Merge pull request 'feat: add terraform_k8s approle' ( #50 ) from benvin/terraform_k8s_approle into master
...
Reviewed-on: #50
2026-02-14 19:38:46 +11:00
unkinben
a47f841028
feat: add terraform_k8s approle
...
- add approle for kubernetes terraform
- ensure it can access consul token for state storage
- ensure it can generate root token for managing kubernetes
2026-02-14 19:37:22 +11:00
unkinben
9192879c03
Merge pull request 'feat: use ephemeral consul token' ( #49 ) from benvin/use_consul_creds into master
...
Reviewed-on: #49
2026-02-14 18:59:56 +11:00
unkinben
5cdf6b410d
feat: use ephemeral consul token
...
- add vault_env to makefile
- retrieve a consul_http_token on demand from vault
2026-02-14 18:59:05 +11:00
unkinben
b51617c009
Merge pull request 'feat: implement consul ACL management with provider aliases' ( #48 ) from benvin/consul_backend into master
...
Reviewed-on: #48
2026-02-14 18:41:49 +11:00
unkinben
66ee6430fa
Merge pull request 'feat: add tf_vault required policies' ( #47 ) from benvin/tf-vault-policy-updates into master
...
Reviewed-on: #47
2026-02-14 18:41:33 +11:00
unkinben
fd03727ec2
feat: add tf_vault required policies
...
move management of Vault back to tf_vault approle. for this, we need to
create a number of policies that are missing.
- add policies to manage consul secret engines
- add policies to manage pki secret engines
- add policies to manage kv secret engines
- add policies to manage ssh secret engines
2026-02-14 18:39:21 +11:00
unkinben
5536869a38
feat: implement consul ACL management with provider aliases
...
This commit message captures the major architectural change of implementing Consul ACL management
with proper provider aliasing, along with the supporting configuration files and policy definitions
for various terraform services.
- add consul_acl_management module to manage consul acl policies and roles
- add consul backend roles and policies for terraform services (incus, k8s, nomad, repoflow, vault)
- add consul provider configuration to root.hcl
- add policies to generate credentials for each role
- simplify consul_secret_backend_role module to reference acl-managed roles
- switch to opentofu for provider foreach support
- update terragrunt configuration to support consul backend aliases
- update pre-commit hooks to use opentofu instead of terraform
- configure tflint exceptions for consul acl management module
2026-02-14 18:13:50 +11:00
unkinben
f8f1185b42
Merge pull request 'chore: add puppet k8s role' ( #46 ) from benvin/puppet_secrets into master
...
Reviewed-on: #46
2026-02-01 14:54:45 +11:00
unkinben
75e9db1aa6
chore: add puppet k8s role
...
- add role and policies
2026-02-01 14:54:23 +11:00
unkinben
f47804ffdf
Merge pull request 'chore: rancher pods use rancher service account' ( #45 ) from benvin/rancher_role into master
...
Reviewed-on: #45
2026-01-30 22:11:53 +11:00
unkinben
24c124d6eb
chore: rancher pods use rancher service account
...
- update bound service account names to be `rancher`
- update namespace to cattle-system (do not run rancher in another namespace)
2026-01-30 22:11:08 +11:00
unkinben
9d54b4cfcc
Merge pull request 'chore: add rancher role' ( #44 ) from benvin/rancher_role into master
...
Reviewed-on: #44
2026-01-30 19:46:19 +11:00
unkinben
33af7010fb
chore: add rancher role
...
- add kubernetes role for rancher
- add policy to enable access to bootstrap-password
2026-01-30 19:43:06 +11:00
unkinben
cb1b383035
Merge pull request 'feat: major restructuring in migration to terragrunt' ( #43 ) from benvin/vault_terragrunt into master
...
Reviewed-on: #43
2026-01-26 23:53:35 +11:00
unkinben
f6d06cb319
chore: cleanup unused config data
...
- remove token_policies from roles config data, this comes from policies.hcl inputs
- remove policies from ldap groups
- remove backend data from roles, this comes from config.hcl inputs
2026-01-26 23:51:50 +11:00
unkinben
1c9e063310
Merge branch 'master' into benvin/vault_terragrunt
2026-01-26 23:07:13 +11:00
unkinben
8070b6f66b
feat: major restructuring in migration to terragrunt
...
- migrate from individual terraform files to config-driven terragrunt module structure
- add vault_cluster module with config discovery system
- replace individual .tf files with centralized config.hcl
- restructure auth and secret backends as configurable modules
- move auth roles and secret backends to yaml-based configuration
- convert policies from .hcl to .yaml format, add rules/auth definition
- add pre-commit hooks for yaml formatting and file cleanup
- add terragrunt cache to gitignore
- update makefile with terragrunt commands and format target
2026-01-26 23:02:44 +11:00
unkinben
b115b7d28a
Merge pull request 'chore: add nzbget secrets' ( #42 ) from benvin/nzbget into master
...
Reviewed-on: #42
2026-01-26 18:31:48 +11:00
unkinben
25e3d48337
chore: add nzbget secrets
...
- add policy for nzbget secrets
- enable the media-apps kubernetes role to use policy
2026-01-26 18:30:49 +11:00
unkinben
fdc801739f
Merge pull request 'feat: add prowlarr access' ( #41 ) from benvin/prowlarr_policy into master
...
Reviewed-on: #41
2026-01-04 23:37:23 +11:00
unkinben
56d858f900
feat: add prowlarr access
...
- enable kubernetes access to prowlarr secrets
2026-01-04 23:36:43 +11:00
unkinben
bd112181f5
Merge pull request 'feat: add policy to read terraform vars' ( #40 ) from benvin/repoflow_terraform into master
...
Reviewed-on: #40
2025-12-13 10:57:33 +11:00
unkinben
4f185d5e28
feat: add policy to read terraform vars
...
- read variables required for terraform-repoflow
2025-12-13 10:56:58 +11:00
unkinben
65ad53e24c
Merge pull request 'feat: add repoflow service vault configuration' ( #39 ) from benvin/repoflow into master
...
Reviewed-on: #39
2025-12-13 10:13:33 +11:00
unkinben
d217f6e42d
Merge pull request 'feat: add repoflow tokens' ( #38 ) from benvin/repoflow_tokens into master
...
Reviewed-on: #38
2025-12-13 10:10:07 +11:00
unkinben
9814b8fc1a
feat: add repoflow tokens
...
- add approle for terraform-repoflow
- add policies to access repoflow tokens
2025-12-13 10:09:29 +11:00
unkinben
7b81abfa9e
feat: add repoflow service vault configuration
...
- add secrets for s3, elasticsearch, hasura, postgres and repoflow
2025-12-13 09:20:58 +11:00
unkinben
2466a6fe5c
Merge pull request 'feat: label kubernetes ephemeral serviceaccounts' ( #37 ) from benvin/k8s_roles_labelling into master
...
Reviewed-on: #37
2025-12-07 12:42:45 +11:00
unkinben
c88b19a216
feat: label kubernetes ephemeral serviceaccounts
...
- ensure all service accounts are labelled with role/cluster
- add additional api endpoints to cluster roles
2025-12-07 12:41:37 +11:00
unkinben
3bada72838
Merge pull request 'chore: allow long lines in yamllint' ( #36 ) from benvin/yamlint-args into master
...
Reviewed-on: #36
2025-12-01 21:51:11 +11:00
unkinben
8961ba3748
chore: allow long lines in yamllint
2025-12-01 21:50:49 +11:00
unkinben
26b3ee84d6
Merge pull request 'chore: fix policies for rpmbuilder' ( #35 ) from benvin/fix_rpmbuilder into master
...
Reviewed-on: #35
2025-11-30 21:24:52 +11:00
unkinben
0776fac6eb
chore: fix policies for rpmbuilder
...
- missed the `/read` on the end
2025-11-30 21:24:06 +11:00
unkinben
3a2ecc9b23
Merge pull request 'feat: add rpmbuilder approle' ( #34 ) from benvin/rpmbuilder into master
...
Reviewed-on: #34
2025-11-29 18:01:37 +11:00
unkinben
5afd1ad9c1
feat: add rpmbuilder approle
...
- add rpmbuilder approle
- add policies to acces gitea/github read-only tokens
2025-11-29 18:00:20 +11:00
unkinben
756286c231
chore: update name, role type for k8s
...
- ensure cluster roles are able to be created as ClusterRole
- prefix all vault managed roles with `vault-`
2025-11-29 00:09:57 +11:00
unkinben
9cc482d471
Merge pull request 'feat: add kubernetes secrets engine with RBAC roles for au-syd1 cluster' ( #33 ) from benvin/au-syd1-k8s-roles into master
...
Reviewed-on: #33
2025-11-27 23:31:04 +11:00
unkinben
6624f7aed1
feat: add kubernetes secrets engine with RBAC roles for au-syd1 cluster
...
- Add Kubernetes secrets engine at kubernetes/au/syd1 path
- Create four RBAC roles with external YAML configuration:
* media-apps-operator: namespaced role for media-apps with selective permissions
* cluster-operator: cluster-wide read-only access to specific API groups
* cluster-admin: cluster-wide full access to specific API groups
* cluster-root: cluster-wide superuser access to all resources
- Add Vault policies for credential generation for each role
- Add admin policies for kubernetes auth backend configuration and role management
- Refactor kubernetes auth backend to use shared locals for CA certificate
- Update terraform-vault approle with required kubernetes policies
2025-11-27 23:22:13 +11:00
unkinben
ad1118af85
Merge pull request 'chore: remove references k8s pki policy' ( #32 ) from benvin/cleanup_k8s_pki_policy_reference into master
...
Reviewed-on: #32
2025-11-27 21:08:29 +11:00
unkinben
cafa887cdc
chore: remove references k8s pki policy
...
- missed from previous pr
- policy no longer exists, remove it from the approle
2025-11-27 21:07:50 +11:00
unkinben
f10f96d19c
Merge pull request 'feat: move state path in consul' ( #31 ) from benvin/move-state-path into master
...
Reviewed-on: #31
2025-11-27 21:05:55 +11:00
unkinben
da0e0e4239
feat: move state path in consul
...
- move state to the infra/terraform/vault subdir
2025-11-27 21:04:44 +11:00
unkinben
2efbf7cc6e
Merge pull request 'chore: remove k8s pki policy' ( #30 ) from benvin/cleanup_k8s_pki into master
...
Reviewed-on: #30
2025-11-27 20:43:08 +11:00
unkinben
b9deb02cfb
chore: remove k8s pki policy
...
- k8s pki engine was removed some time ago
- also cleanup policy files
2025-11-27 20:42:27 +11:00
unkinben
391c77d30b
Merge pull request 'feat: add media-apps integration with vault' ( #29 ) from benvin/media_apps_k8s into master
...
Reviewed-on: #29
2025-11-27 20:41:52 +11:00
unkinben
6353ac6bbc
feat: add media-apps integration with vault
...
- add kubernetes auth role for media-apps
- add policies to read radarr/sonarr secrets
2025-11-27 20:40:54 +11:00
unkinben
605aa204a9
Merge pull request 'chore: update k8s csi roles' ( #28 ) from benvin/ceph-csi-changes into master
...
Reviewed-on: #28
2025-11-26 21:01:58 +11:00
unkinben
4cf1b43960
chore: update k8s csi roles
...
- ensure the new service accounts can read cephrbd/cephfs
- ensure correct namespace is allowed
2025-11-26 21:01:31 +11:00
unkinben
f217dbaeca
Merge pull request 'feat: manage k8s auth role integration' ( #27 ) from benvin/k8s_roles_integration into master
...
Reviewed-on: #27
2025-11-22 23:23:13 +11:00
unkinben
7814551084
feat: manage k8s auth role integration
...
- add policies to sign/issue certificates
- manage auth roles for ceph-csi, certmanager, externaldns, huntarr
2025-11-22 23:21:43 +11:00
unkinben
85cda88a3b
Merge pull request 'chore: fix kubernetes_host' ( #26 ) from benvin/kubernetes_host into master
...
Reviewed-on: #26
2025-11-16 16:50:13 +11:00
unkinben
02654ac32a
chore: fix kubernetes_host
...
- correct hostname to match `kubectl cluster-info`
- fix formatting with terraform fmt
2025-11-16 16:49:04 +11:00
unkinben
c3c1cb660a
Merge pull request 'benvin/pre-commit' ( #25 ) from benvin/pre-commit into master
...
Reviewed-on: #25
2025-11-16 13:37:55 +11:00
unkinben
5cbd5815a0
chore: format policy files
...
- ensure all policy files are correctly formatted
2025-11-16 13:35:10 +11:00
unkinben
6d84efe81e
feat: add pre-commit
...
- ran 'pre-commit install'
- add pre-commit configuration
- test yaml + terraform related checks
- terragrunt-hcl-fmt for policy hcl files
2025-11-16 13:31:16 +11:00
unkinben
9ff6cf7de7
Merge pull request 'chore: add terraform required version' ( #24 ) from benvin/terraform_required_version into master
...
Reviewed-on: #24
2025-11-16 13:13:44 +11:00
unkinben
865a97ba0e
Merge pull request 'feat: rework policies file' ( #23 ) from benvin/policy_rework into master
...
Reviewed-on: #23
2025-11-16 13:13:37 +11:00
unkinben
c0d0888172
chore: add terraform required version
...
- set the terraform required version to 1.10+
2025-11-16 13:13:08 +11:00
unkinben
49889eaf22
feat: rework policies file
...
- policy files are now found automatically
2025-11-16 13:08:50 +11:00
unkinben
d2acaeb7bc
Merge pull request 'feat: move k8s secrets into vault' ( #22 ) from benvin/kubernetes_secret_handling into master
...
Reviewed-on: #22
2025-11-16 12:44:40 +11:00
unkinben
cbee19b5f9
feat: move k8s secrets into vault
...
- update kubernetes_host to match value in jwt
- regenerate jwt token and store in vault
- add policy to enable access to jwt token
- update tf_deploy user with access to token
2025-11-16 12:42:18 +11:00
unkinben
353d726510
Merge pull request 'feat: add makefile' ( #21 ) from benvin/makefile into master
...
Reviewed-on: #21
2025-11-16 12:40:25 +11:00
unkinben
537cc9013a
feat: add makefile
...
- add init, plan and apply to makefile
2025-11-16 12:39:32 +11:00
unkinben
8e1d242dba
Merge pull request 'feat: add transit engine' ( #20 ) from benvin/transit_engine into master
...
Reviewed-on: #20
2025-11-15 15:57:04 +11:00
unkinben
85d81fef72
feat: add transit engine
...
- add transit engine
- add policies to manage keys, encryption and decryption
- add ability to create keys to tf_vault approle
2025-11-15 15:55:51 +11:00
unkinben
59b7b01c23
Merge pull request 'feat: enable annotations as alias metadata' ( #19 ) from benvin/annotations_as_alias_metadata into master
...
Reviewed-on: #19
2025-11-15 15:41:42 +11:00
unkinben
5675a469da
feat: enable annotations as alias metadata
...
- enable the ability to set additional alias metadata via annotations
2025-11-15 15:40:54 +11:00
unkinben
489969fed8
Merge pull request 'feat: upgrade vault provider' ( #18 ) from benvin/upgrade_provider into master
...
Reviewed-on: #18
2025-11-15 15:40:16 +11:00
unkinben
1ee07dd52f
feat: upgrade vault provider
...
- upgrade to hashicorp/vault 5.4.0
2025-11-15 15:38:22 +11:00
unkinben
0869b6f723
Merge pull request 'feat: add kubernetes auth engine' ( #17 ) from benvin/k8s_auth into master
...
Reviewed-on: #17
2025-11-15 10:51:18 +11:00
unkinben
bc9b4eebdc
feat: add kubernetes auth engine
...
- add kubernetes authentication
- add policy to manage kubernetes auth engine roles/config
2025-11-15 10:50:17 +11:00
unkinben
9f4b77a765
Merge pull request 'feat: update policy names to be path based' ( #16 ) from benvin/policy_rework into master
...
Reviewed-on: #16
2025-11-15 10:49:19 +11:00
unkinben
4364b444fd
feat: update policy names to be path based
...
- change policy names to be based on the path they are stored at
2025-11-15 10:48:17 +11:00
unkinben
fee61c3eb5
Merge pull request 'feat: add new puppetca' ( #15 ) from benvin/new_puppetca into master
...
Reviewed-on: #15
2025-07-10 21:51:02 +10:00
unkinben
23e3fb88ea
feat: add new puppetca
...
- update puppetmaster/puppetca cidrs
2025-07-10 21:49:36 +10:00
unkinben
8fd8913554
Merge pull request 'feat: add new puppetmasters to vault approles' ( #14 ) from benvin/new_puppetmasters into master
...
Reviewed-on: https://git.query.consul/unkin/terraform-vault/pulls/14
2025-05-31 15:17:40 +10:00
unkinben
1f35fec37c
feat: add new puppetmasters to vault approles
2025-05-31 15:17:22 +10:00
unkinben
b46d36d03b
Merge pull request 'feat: update gitea runners' ( #13 ) from benvin/update_runners into master
...
Reviewed-on: https://git.query.consul/unkin/terraform-vault/pulls/13
2025-05-25 10:32:37 +10:00
unkinben
ac36f9355c
feat: update gitea runners
...
- changed gitea runners, updating cidrs
2025-05-25 10:31:29 +10:00
unkinben
50d1e31ea5
Merge pull request 'feat: enable access to puppetcerts' ( #12 ) from neoloc/puppet_terraform into master
...
Reviewed-on: https://git.query.consul/unkin/terraform-vault/pulls/12
2025-04-27 16:26:25 +10:00
unkinben
d508dcd4a9
feat: enable access to puppetcerts
...
- enable the terraform-incus repo to access puppet certs
2025-04-27 16:26:05 +10:00
unkinben
4aac926c6a
Merge pull request 'feat: enable access to kv/service/packer/builder/docker-incus-client' ( #11 ) from neoloc/add_packer_path into master
...
Reviewed-on: https://git.query.consul/unkin/terraform-vault/pulls/11
2025-04-23 18:25:28 +10:00
unkinben
05268f9dd8
feat: enable access to kv/service/packer/builder/docker-incus-client
2025-04-23 18:24:36 +10:00
unkinben
80c14ef4e4
Merge pull request 'neoloc/incus' ( #10 ) from neoloc/incus into master
...
Reviewed-on: https://git.query.consul/unkin/terraform-vault/pulls/10
2025-04-07 16:27:29 +10:00
unkinben
feee7a265e
feat: remove k8s pki engines
2025-04-07 16:25:52 +10:00
unkinben
8bc67e1e5b
feat: add terraform-incus approle/policy
2025-04-07 16:22:41 +10:00
unkinben
275b640adc
feat: add packer-builder policy
2025-04-07 16:22:22 +10:00
unkinben
2dc37cc8c4
Merge pull request 'feat: add pki for k8s' ( #9 ) from neoloc/k8s_pki into master
...
Reviewed-on: https://git.query.consul/unkin/terraform-vault/pulls/9
2025-01-27 21:06:30 +11:00
unkinben
9b9afdce58
feat: add pki for k8s
...
- add pki for k8s
- add policy to manage k8s/*/roles/*
2025-01-27 21:05:51 +11:00
unkinben
cd9c006203
Merge pull request 'fix: fix rolename' ( #8 ) from neoloc/oops into master
...
Reviewed-on: https://git.query.consul/unkin/terraform-vault/pulls/8
2025-01-11 21:33:04 +11:00
unkinben
2d345cc63b
fix: fix rolename
...
- had duplicate role
- change policy name to match approle
- updated ttl as packer builds can take some time
2025-01-11 21:32:33 +11:00
unkinben
99b643b458
Merge pull request 'feat: add packer-builder role' ( #7 ) from neoloc/packer-builder into master
...
Reviewed-on: https://git.query.consul/unkin/terraform-vault/pulls/7
2025-01-11 21:06:36 +11:00
unkinben
f83ba13158
feat: add packer-builder role
...
- limit access to workstation and gitea runners
2025-01-11 21:01:17 +11:00
unkinben
e4d80e42dc
Merge pull request 'feat: add incus-cluster role/policies' ( #6 ) from neoloc/incus into master
...
Reviewed-on: https://git.query.consul/unkin/terraform-vault/pulls/6
2025-01-06 23:16:53 +11:00
unkinben
12e04b3db7
feat: add incus-cluster role/policies
...
- add policy and role to manage incus cluster join tokens
2025-01-06 23:16:06 +11:00
unkinben
aa518c1b44
Merge pull request 'feat: add terraform_nomad role' ( #5 ) from neoloc/nomad into master
...
Reviewed-on: https://git.query.consul/unkin/terraform-vault/pulls/5
2024-12-28 17:15:04 +11:00
unkinben
fc22ac1711
feat: add terraform_nomad role
...
- add approle and policy for nomad terraform
2024-12-28 17:14:14 +11:00
unkinben
d5bd00d8ab
Merge pull request 'feat: add puppetapi approle/policy' ( #4 ) from neoloc/puppetapi into master
...
Reviewed-on: https://git.query.consul/unkin/terraform-vault/pulls/4
2024-12-15 17:07:29 +11:00
unkinben
63dd355311
feat: add puppetapi approle/policy
2024-12-15 17:07:01 +11:00
unkinben
bfda3f2f72
Merge pull request 'fix: fix vault_* groups' ( #3 ) from neoloc/fix_group into master
...
Reviewed-on: https://git.query.consul/unkin/terraform-vault/pulls/3
2024-10-21 20:02:14 +11:00
unkinben
f597e0a979
fix: fix vault_* groups
...
- fix vault_admin group
2024-10-21 20:01:21 +11:00
unkinben
fd0fe2403b
Merge pull request 'feat: add vault admin group' ( #2 ) from neoloc/vault_admin_ldapgroup into master
...
Reviewed-on: https://git.query.consul/unkin/terraform-vault/pulls/2
2024-10-21 19:43:24 +11:00
unkinben
bcdb81e060
feat: add vault admin group
...
- assign global-admin policy
2024-10-21 19:42:49 +11:00
unkinben
9e3cbce264
Merge pull request 'neoloc/terraformvault' ( #1 ) from neoloc/terraformvault into master
...
Reviewed-on: https://git.query.consul/unkin/terraform-vault/pulls/1
2024-09-26 23:06:26 +10:00
unkinben
f78416361b
feat: manage terraform access to vault
...
- add approle for terraform, tf_vault
- add policices to manage terraform access to vault
- add policices for default access to vault from ldap users
2024-09-26 22:59:40 +10:00