Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 1dace21b37 |
@@ -1,9 +0,0 @@
|
||||
# Mounts the arrstack dynamic secrets engine at "arrstack" and writes its config.
|
||||
# The arrproxy admin token is sensitive and read from KV, not stored here:
|
||||
# kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token -> key "token"
|
||||
# (seeded by argocd-apps #384). arrstack.unkin.net terminates on traefik-external
|
||||
# with an internal-CA cert the OpenBao nodes already trust, so ca_cert is omitted
|
||||
# (system trust store), mirroring the gitea engine against git.unkin.net.
|
||||
description: "arrstack dynamic arrproxy API keys"
|
||||
base_url: "https://arrstack.unkin.net"
|
||||
request_timeout_seconds: 30
|
||||
@@ -1,9 +0,0 @@
|
||||
---
|
||||
# Mints an arrproxy API key scoped to all three arr apps.
|
||||
apps:
|
||||
- sonarr
|
||||
- radarr
|
||||
- prowlarr
|
||||
ttl: 3600 # seconds (1h)
|
||||
max_ttl: 86400 # seconds (24h); the engine additionally caps renewal at the
|
||||
# arrproxy admin token's fixed mint expiry.
|
||||
@@ -1,7 +0,0 @@
|
||||
---
|
||||
# Mints an arrproxy API key scoped to Prowlarr only.
|
||||
apps:
|
||||
- prowlarr
|
||||
ttl: 3600 # seconds (1h)
|
||||
max_ttl: 86400 # seconds (24h); the engine additionally caps renewal at the
|
||||
# arrproxy admin token's fixed mint expiry.
|
||||
@@ -1,7 +0,0 @@
|
||||
---
|
||||
# Mints an arrproxy API key scoped to Radarr only.
|
||||
apps:
|
||||
- radarr
|
||||
ttl: 3600 # seconds (1h)
|
||||
max_ttl: 86400 # seconds (24h); the engine additionally caps renewal at the
|
||||
# arrproxy admin token's fixed mint expiry.
|
||||
@@ -1,7 +0,0 @@
|
||||
---
|
||||
# Mints an arrproxy API key scoped to Sonarr only.
|
||||
apps:
|
||||
- sonarr
|
||||
ttl: 3600 # seconds (1h)
|
||||
max_ttl: 86400 # seconds (24h); the engine additionally caps renewal at the
|
||||
# arrproxy admin token's fixed mint expiry.
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- ghp
|
||||
bound_service_account_namespaces:
|
||||
- ghp
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: vault
|
||||
@@ -198,19 +198,6 @@ locals {
|
||||
})
|
||||
if startswith(file_path, "litellm_secret_backend_role/")
|
||||
}
|
||||
arrstack_secret_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(basename(file_path), ".yaml") => content
|
||||
if startswith(file_path, "arrstack_secret_backend/")
|
||||
}
|
||||
arrstack_secret_backend_role = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "arrstack_secret_backend_role/", ""), ".yaml") => merge(content, {
|
||||
name = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = dirname(replace(file_path, "arrstack_secret_backend_role/", ""))
|
||||
})
|
||||
if startswith(file_path, "arrstack_secret_backend_role/")
|
||||
}
|
||||
plugins = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(basename(file_path), ".yaml") => merge(content, {
|
||||
@@ -279,18 +266,5 @@ locals {
|
||||
})
|
||||
if startswith(file_path, "netbox_secret_backend_role/")
|
||||
}
|
||||
ghp_secret_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(basename(file_path), ".yaml") => content
|
||||
if startswith(file_path, "ghp_secret_backend/")
|
||||
}
|
||||
ghp_secret_backend_role = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "ghp_secret_backend_role/", ""), ".yaml") => merge(content, {
|
||||
name = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = dirname(replace(file_path, "ghp_secret_backend_role/", ""))
|
||||
})
|
||||
if startswith(file_path, "ghp_secret_backend_role/")
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,15 +0,0 @@
|
||||
# Mounts the ghp token secrets engine at "ghp" and writes its config.
|
||||
# The seeded ghp service token is sensitive and read from KV, not stored here:
|
||||
# kv/service/vault/au/syd1/secret_backend/ghp/config
|
||||
# -> key: admin_token (required) the shared ghpsvc_... service token
|
||||
#
|
||||
# admin_token is a static shared secret provisioned into KV by an operator. The
|
||||
# SAME token value must also be present in the running ghp deployment's accepted
|
||||
# service tokens (GHP_AUTH_SERVICE_TOKENS) so ghp ACCEPTS what this engine
|
||||
# PRESENTS. ghp has no rotate endpoint, so the engine never rotates it in place;
|
||||
# the mount uses ignore_changes=[admin_token], making the KV seed create-only
|
||||
# (re-reading a stale KV value never re-pushes it to a live mount).
|
||||
description: "ghp ephemeral scoped agent token engine"
|
||||
base_url: "https://ghp.unkin.net"
|
||||
tls_skip_verify: false
|
||||
request_timeout_seconds: 30
|
||||
@@ -1,15 +0,0 @@
|
||||
# Role minting ephemeral, scoped ghp agent tokens. Reading ghp/creds/agent mints
|
||||
# a lease-bound token deleted from ghp on revoke/expiry. token_type "agent" binds
|
||||
# the minted token to a ghp App installation, so installation_id is REQUIRED.
|
||||
#
|
||||
# installation_id below is a PLACEHOLDER (0) and MUST be set to the real ghp App
|
||||
# installation id before this role can mint usable tokens. scopes are ghp
|
||||
# permission:level pairs; contents:read is the least-privilege default.
|
||||
---
|
||||
token_type: agent
|
||||
installation_id: 0 # PLACEHOLDER - set to the real ghp App installation id
|
||||
scopes:
|
||||
- contents:read
|
||||
session_prefix: vault
|
||||
ttl: 3600 # 1h
|
||||
max_ttl: 86400 # 24h
|
||||
@@ -1,13 +0,0 @@
|
||||
# config/plugins/vault-plugin-secrets-arrstack.yaml
|
||||
# Imports (registers) the arrstack secrets plugin in the catalog. Filename =
|
||||
# catalog name = mount type. The binary is installed on the OpenBao nodes by
|
||||
# Puppet (openbao-plugin-secrets-arrstack RPM ->
|
||||
# /opt/openbao-plugins/vault-plugin-secrets-arrstack).
|
||||
#
|
||||
# sha256 pins the released v0.1.0 binary; bump it in lockstep with any RPM
|
||||
# upgrade or OpenBao will refuse to launch the plugin. Registration only
|
||||
# succeeds once the Puppet PR has installed the binary on the nodes.
|
||||
type: secret
|
||||
command: vault-plugin-secrets-arrstack
|
||||
version: "0.1.0"
|
||||
sha256: "f8ee60ca7ba14819976acb7dc4cfb6799e3e8da8f871d0bb2bd18d1d9e537972"
|
||||
@@ -1,11 +0,0 @@
|
||||
# config/plugins/vault-plugin-secrets-ghp.yaml
|
||||
# Imports (registers) the ghp secrets plugin in the catalog. Filename =
|
||||
# catalog name = mount type. The binary is installed on the OpenBao nodes by
|
||||
# Puppet (openbao-plugin-secrets-ghp RPM ->
|
||||
# /opt/openbao-plugins/vault-plugin-secrets-ghp).
|
||||
#
|
||||
# sha256 pins the released v0.1.0 binary; bump it in lockstep with any RPM
|
||||
# upgrade or OpenBao will refuse to launch the plugin.
|
||||
type: secret
|
||||
command: vault-plugin-secrets-ghp
|
||||
sha256: "85761421cd532788ed28fb57e93d3868f3577320a538289936d9ed3be5f396de"
|
||||
@@ -76,8 +76,6 @@ inputs = {
|
||||
pki_mount_only = local.config.pki_mount_only
|
||||
litellm_secret_backend = local.config.litellm_secret_backend
|
||||
litellm_secret_backend_role = local.config.litellm_secret_backend_role
|
||||
arrstack_secret_backend = local.config.arrstack_secret_backend
|
||||
arrstack_secret_backend_role = local.config.arrstack_secret_backend_role
|
||||
plugins = local.config.plugins
|
||||
gpg_secret_backend = local.config.gpg_secret_backend
|
||||
gpg_key = local.config.gpg_key
|
||||
@@ -92,9 +90,6 @@ inputs = {
|
||||
netbox_secret_backend = local.config.netbox_secret_backend
|
||||
netbox_secret_backend_role = local.config.netbox_secret_backend_role
|
||||
|
||||
ghp_secret_backend = local.config.ghp_secret_backend
|
||||
ghp_secret_backend_role = local.config.ghp_secret_backend_role
|
||||
|
||||
# Pass policy maps to vault_cluster module
|
||||
policy_auth_map = local.policies.policy_auth_map
|
||||
policy_rules_map = local.policies.policy_rules_map
|
||||
|
||||
@@ -29,12 +29,6 @@ provider "rancher" {
|
||||
address = local.vault_addr
|
||||
}
|
||||
|
||||
# The arrstack (arrproxy API key) secrets engine is managed through its own
|
||||
# provider (same Vault server; token falls back to VAULT_TOKEN).
|
||||
provider "arrstack" {
|
||||
address = local.vault_addr
|
||||
}
|
||||
|
||||
terraform {
|
||||
backend "consul" {
|
||||
address = "https://consul.service.consul"
|
||||
@@ -65,10 +59,6 @@ terraform {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/ranchervaultsecret"
|
||||
version = "0.1.0"
|
||||
}
|
||||
arrstack = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/arrstackvaultsecret"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
EOF
|
||||
|
||||
@@ -347,35 +347,6 @@ module "plugin" {
|
||||
plugin_version = each.value.version
|
||||
}
|
||||
|
||||
module "arrstack_secret_backend" {
|
||||
source = "./modules/arrstack_secret_backend"
|
||||
|
||||
for_each = var.arrstack_secret_backend
|
||||
|
||||
path = each.key
|
||||
plugin = each.value.plugin
|
||||
description = each.value.description
|
||||
base_url = each.value.base_url
|
||||
ca_cert = each.value.ca_cert
|
||||
request_timeout_seconds = each.value.request_timeout_seconds
|
||||
|
||||
depends_on = [module.plugin]
|
||||
}
|
||||
|
||||
module "arrstack_secret_backend_role" {
|
||||
source = "./modules/arrstack_secret_backend_role"
|
||||
|
||||
for_each = var.arrstack_secret_backend_role
|
||||
|
||||
name = each.value.name
|
||||
backend = each.value.backend
|
||||
apps = each.value.apps
|
||||
ttl = each.value.ttl
|
||||
max_ttl = each.value.max_ttl
|
||||
|
||||
depends_on = [module.arrstack_secret_backend]
|
||||
}
|
||||
|
||||
module "gpg_secret_backend" {
|
||||
source = "./modules/gpg_secret_backend"
|
||||
|
||||
@@ -565,43 +536,6 @@ module "netbox_secret_backend_role" {
|
||||
depends_on = [module.netbox_secret_backend, module.netbox_user_management]
|
||||
}
|
||||
|
||||
module "ghp_secret_backend" {
|
||||
source = "./modules/ghp_secret_backend"
|
||||
|
||||
for_each = var.ghp_secret_backend
|
||||
|
||||
path = each.key
|
||||
plugin = each.value.plugin
|
||||
description = each.value.description
|
||||
base_url = each.value.base_url
|
||||
country = var.country
|
||||
region = var.region
|
||||
ca_cert = each.value.ca_cert
|
||||
tls_skip_verify = each.value.tls_skip_verify
|
||||
request_timeout_seconds = each.value.request_timeout_seconds
|
||||
|
||||
depends_on = [module.plugin]
|
||||
}
|
||||
|
||||
module "ghp_secret_backend_role" {
|
||||
source = "./modules/ghp_secret_backend_role"
|
||||
|
||||
for_each = var.ghp_secret_backend_role
|
||||
|
||||
backend = each.value.backend
|
||||
name = each.value.name
|
||||
token_type = each.value.token_type
|
||||
installation_id = each.value.installation_id
|
||||
app_record_id = each.value.app_record_id
|
||||
repositories = each.value.repositories
|
||||
scopes = each.value.scopes
|
||||
session_prefix = each.value.session_prefix
|
||||
ttl = each.value.ttl
|
||||
max_ttl = each.value.max_ttl
|
||||
|
||||
depends_on = [module.ghp_secret_backend]
|
||||
}
|
||||
|
||||
module "vault_policy" {
|
||||
source = "./modules/vault_policy"
|
||||
|
||||
|
||||
@@ -1,20 +0,0 @@
|
||||
# Mounts the arrstack dynamic secrets engine and writes its config via the
|
||||
# arrstackvaultsecret provider. The plugin is registered in the catalog
|
||||
# separately (config/plugins/vault-plugin-secrets-arrstack.yaml). The arrproxy
|
||||
# admin token is sensitive and read from KV, not stored in git:
|
||||
# kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token -> key "token"
|
||||
# (seeded by argocd-apps #384).
|
||||
data "vault_kv_secret_v2" "admin_token" {
|
||||
mount = "kv"
|
||||
name = var.admin_token_kv_name
|
||||
}
|
||||
|
||||
resource "arrstack_secret_backend" "this" {
|
||||
path = var.path
|
||||
plugin = var.plugin
|
||||
description = var.description
|
||||
base_url = var.base_url
|
||||
admin_token = data.vault_kv_secret_v2.admin_token.data[var.admin_token_kv_key]
|
||||
ca_cert = var.ca_cert
|
||||
request_timeout_seconds = var.request_timeout_seconds
|
||||
}
|
||||
@@ -1,13 +0,0 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
vault = {
|
||||
source = "hashicorp/vault"
|
||||
version = "5.6.0"
|
||||
}
|
||||
arrstack = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/arrstackvaultsecret"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1,45 +0,0 @@
|
||||
variable "path" {
|
||||
description = "Mount path of the arrstack secrets engine (e.g. \"arrstack\")"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "plugin" {
|
||||
description = "Registered plugin name/type to mount (the catalog name = mount type)"
|
||||
type = string
|
||||
default = "vault-plugin-secrets-arrstack"
|
||||
}
|
||||
|
||||
variable "description" {
|
||||
description = "Human-friendly description of the mount"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "base_url" {
|
||||
description = "Base URL of the arrproxy front door (e.g. https://arrstack.unkin.net)"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "admin_token_kv_name" {
|
||||
description = "kv-v2 secret name (relative to the \"kv\" mount) holding the seeded arrproxy admin token"
|
||||
type = string
|
||||
default = "kubernetes/namespace/arrstack/default/arrproxy-admin-token"
|
||||
}
|
||||
|
||||
variable "admin_token_kv_key" {
|
||||
description = "Key within the KV secret that holds the arrproxy admin token"
|
||||
type = string
|
||||
default = "token"
|
||||
}
|
||||
|
||||
variable "ca_cert" {
|
||||
description = "PEM CA certificate that signed the arrproxy server's TLS cert (optional; omit to use the system trust store)"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "request_timeout_seconds" {
|
||||
description = "HTTP timeout in seconds for calls from the plugin to arrproxy"
|
||||
type = number
|
||||
default = 30
|
||||
}
|
||||
@@ -1,7 +0,0 @@
|
||||
resource "arrstack_secret_backend_role" "this" {
|
||||
backend = var.backend
|
||||
name = var.name
|
||||
apps = var.apps
|
||||
ttl = var.ttl
|
||||
max_ttl = var.max_ttl
|
||||
}
|
||||
@@ -1,9 +0,0 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
arrstack = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/arrstackvaultsecret"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1,26 +0,0 @@
|
||||
variable "name" {
|
||||
description = "Name of the role"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "backend" {
|
||||
description = "Mount path of the arrstack secrets engine this role belongs to"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "apps" {
|
||||
description = "arr apps a generated key may access (subset of sonarr, radarr, prowlarr)"
|
||||
type = list(string)
|
||||
}
|
||||
|
||||
variable "ttl" {
|
||||
description = "Default lease TTL in seconds for keys generated from this role"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "max_ttl" {
|
||||
description = "Maximum lease TTL in seconds for keys generated from this role"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
@@ -1,31 +0,0 @@
|
||||
# Mounts the ghp secrets engine and writes its connection config via the
|
||||
# vault-secrets-ghp provider. The plugin is registered ("imported") in the
|
||||
# catalog separately (config/plugins/vault-plugin-secrets-ghp.yaml). The seeded
|
||||
# ghp service token is sensitive and read from KV, not stored in git:
|
||||
# kv/service/vault/<country>/<region>/secret_backend/<path>/config
|
||||
# Expected key: admin_token (a ghpsvc_... service token that ghp accepts via its
|
||||
# GHP_AUTH_SERVICE_TOKENS list). ghp has no rotate endpoint, so this static
|
||||
# shared secret is the single credential the engine authenticates with.
|
||||
data "vault_kv_secret_v2" "config" {
|
||||
mount = "kv"
|
||||
name = "service/vault/${var.country}/${var.region}/secret_backend/${var.path}/config"
|
||||
}
|
||||
|
||||
resource "ghp_secret_backend" "this" {
|
||||
path = var.path
|
||||
plugin = var.plugin
|
||||
description = var.description
|
||||
base_url = var.base_url
|
||||
admin_token = data.vault_kv_secret_v2.config.data["admin_token"]
|
||||
ca_cert = var.ca_cert
|
||||
tls_skip_verify = var.tls_skip_verify
|
||||
request_timeout_seconds = var.request_timeout_seconds
|
||||
|
||||
lifecycle {
|
||||
# The KV seed is a bootstrap credential consumed only when the engine config
|
||||
# is first created. ghp has no rotate endpoint, so re-reading a (possibly
|
||||
# stale) KV value must never re-push it into the live mount. Ignoring the
|
||||
# token makes this module create-only for it (mirrors gitea/netbox config).
|
||||
ignore_changes = [admin_token]
|
||||
}
|
||||
}
|
||||
@@ -1,13 +0,0 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
vault = {
|
||||
source = "hashicorp/vault"
|
||||
version = "5.6.0"
|
||||
}
|
||||
ghp = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/vault-secrets-ghp"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1,49 +0,0 @@
|
||||
variable "path" {
|
||||
description = "Mount path of the ghp secrets engine (e.g. \"ghp\")"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "plugin" {
|
||||
description = "Registered plugin name to mount (the catalog name = mount type)"
|
||||
type = string
|
||||
default = "vault-plugin-secrets-ghp"
|
||||
}
|
||||
|
||||
variable "description" {
|
||||
description = "Human-friendly description of the mount"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "base_url" {
|
||||
description = "Base URL of the ghp server (e.g. https://ghp.unkin.net)"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "country" {
|
||||
description = "Country segment of the KV path holding the seeded admin token"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "region" {
|
||||
description = "Region segment of the KV path holding the seeded admin token"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "ca_cert" {
|
||||
description = "PEM CA certificate that signed the ghp server's TLS cert (optional; omit to use the system trust store)"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "tls_skip_verify" {
|
||||
description = "Skip TLS verification of the ghp server (not recommended)"
|
||||
type = bool
|
||||
default = false
|
||||
}
|
||||
|
||||
variable "request_timeout_seconds" {
|
||||
description = "HTTP timeout in seconds for calls from the plugin to ghp"
|
||||
type = number
|
||||
default = 30
|
||||
}
|
||||
@@ -1,15 +0,0 @@
|
||||
# A role that mints short-lived, scoped ghp tokens. Reading ghp/creds/<name>
|
||||
# produces a lease-bound token that is revoked from ghp when the lease is
|
||||
# revoked or reaches max_ttl.
|
||||
resource "ghp_secret_role" "this" {
|
||||
backend = var.backend
|
||||
name = var.name
|
||||
token_type = var.token_type
|
||||
installation_id = var.installation_id
|
||||
app_record_id = var.app_record_id
|
||||
repositories = var.repositories
|
||||
scopes = var.scopes
|
||||
session_prefix = var.session_prefix
|
||||
ttl = var.ttl
|
||||
max_ttl = var.max_ttl
|
||||
}
|
||||
@@ -1,9 +0,0 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
ghp = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/vault-secrets-ghp"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1,57 +0,0 @@
|
||||
variable "backend" {
|
||||
description = "Mount path of the ghp secrets engine this role belongs to"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "name" {
|
||||
description = "Role name (read ghp/creds/<name> to mint a token)"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "token_type" {
|
||||
description = "ghp token type to mint: \"agent\" (default) or \"proxy\""
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "installation_id" {
|
||||
description = "ghp App installation id the minted agent token is bound to (required when token_type is \"agent\")"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "app_record_id" {
|
||||
description = "Optional ghp App record id (UUID) to pin agent tokens to; empty selects ghp's default app"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "repositories" {
|
||||
description = "Optional repositories the minted token is restricted to; empty is open-scoped (all repositories)"
|
||||
type = list(string)
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "scopes" {
|
||||
description = "Optional ghp permission:level scopes (e.g. [\"contents:read\"]); empty is open-scoped"
|
||||
type = list(string)
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "session_prefix" {
|
||||
description = "Prefix for the ghp session id of each minted token (default \"vault\")"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "ttl" {
|
||||
description = "Default lease TTL in seconds for minted tokens"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "max_ttl" {
|
||||
description = "Maximum lease TTL in seconds for minted tokens"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
@@ -316,30 +316,6 @@ variable "litellm_secret_backend_role" {
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "arrstack_secret_backend" {
|
||||
description = "Map of arrstack secret engines to create (mount + config). The arrproxy admin token is read from KV"
|
||||
type = map(object({
|
||||
plugin = optional(string, "vault-plugin-secrets-arrstack")
|
||||
description = optional(string)
|
||||
base_url = string
|
||||
ca_cert = optional(string)
|
||||
request_timeout_seconds = optional(number, 30)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "arrstack_secret_backend_role" {
|
||||
description = "Map of arrstack roles to create"
|
||||
type = map(object({
|
||||
name = string
|
||||
backend = string
|
||||
apps = list(string)
|
||||
ttl = optional(number)
|
||||
max_ttl = optional(number)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "plugins" {
|
||||
description = "Map of plugins to import (register) in the catalog, keyed by catalog name"
|
||||
type = map(object({
|
||||
@@ -492,36 +468,6 @@ variable "netbox_backend_aliases" {
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "ghp_secret_backend" {
|
||||
description = "Map of ghp token secret engines to create (mount + config; seeded service token read from KV)"
|
||||
type = map(object({
|
||||
plugin = optional(string, "vault-plugin-secrets-ghp")
|
||||
description = optional(string)
|
||||
base_url = string
|
||||
ca_cert = optional(string)
|
||||
tls_skip_verify = optional(bool, false)
|
||||
request_timeout_seconds = optional(number, 30)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "ghp_secret_backend_role" {
|
||||
description = "Map of ghp engine roles; reading ghp/creds/<name> mints a short-lived scoped ghp token"
|
||||
type = map(object({
|
||||
name = string
|
||||
backend = string
|
||||
token_type = optional(string)
|
||||
installation_id = optional(number)
|
||||
app_record_id = optional(string)
|
||||
repositories = optional(list(string))
|
||||
scopes = optional(list(string))
|
||||
session_prefix = optional(string)
|
||||
ttl = optional(number)
|
||||
max_ttl = optional(number)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "policy_auth_map" {
|
||||
description = "Map of auth mounts -> auth roles -> policy names"
|
||||
type = map(map(list(string)))
|
||||
|
||||
@@ -1,27 +0,0 @@
|
||||
# Allow management of the arrstack secrets engine (config and roles) by the
|
||||
# terraform-vault deployer.
|
||||
---
|
||||
rules:
|
||||
- path: "arrstack/config"
|
||||
capabilities:
|
||||
- create
|
||||
- update
|
||||
- read
|
||||
- delete
|
||||
- path: "arrstack/roles/*"
|
||||
capabilities:
|
||||
- create
|
||||
- update
|
||||
- delete
|
||||
- read
|
||||
- list
|
||||
- path: "arrstack/roles"
|
||||
capabilities:
|
||||
- read
|
||||
- list
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- tf_vault
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_vault
|
||||
@@ -1,12 +0,0 @@
|
||||
# Allow the terraform-prowlarr run to mint a Prowlarr-scoped arrproxy key.
|
||||
---
|
||||
rules:
|
||||
- path: "arrstack/creds/prowlarr"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- terraform_prowlarr
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_prowlarr
|
||||
@@ -1,12 +0,0 @@
|
||||
# Allow the terraform-radarr run to mint a Radarr-scoped arrproxy key.
|
||||
---
|
||||
rules:
|
||||
- path: "arrstack/creds/radarr"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- terraform_radarr
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_radarr
|
||||
@@ -1,12 +0,0 @@
|
||||
# Allow the terraform-sonarr run to mint a Sonarr-scoped arrproxy key.
|
||||
---
|
||||
rules:
|
||||
- path: "arrstack/creds/sonarr"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- terraform_sonarr
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_sonarr
|
||||
@@ -1,37 +0,0 @@
|
||||
# Allow the vault deployer to manage the ghp token secrets engine: its
|
||||
# connection config (seeded service token) and its token-minting roles.
|
||||
#
|
||||
# Scoped to ghp/* only, and deliberately excludes ghp/creds/* - minting tokens
|
||||
# is for consumers, not the deployer. ghp has NO rotate endpoint, so unlike the
|
||||
# gitea/netbox engines there is no config/rotate grant here. The plugin-catalog
|
||||
# grant needed to import the plugin is the shared, sudo-protected wildcard in
|
||||
# policies/sys/plugins/catalog/admin.yaml (already covers this plugin), and
|
||||
# mounting the engine uses the deployer's existing sys/mounts/* access, so no
|
||||
# new catalog/mount grant is added here (mirrors the gitea/netbox engines).
|
||||
---
|
||||
rules:
|
||||
# Engine connection config (base_url, TLS, seeded service token).
|
||||
- path: "ghp/config"
|
||||
capabilities:
|
||||
- create
|
||||
- read
|
||||
- update
|
||||
- delete
|
||||
# Token-minting roles.
|
||||
- path: "ghp/roles/*"
|
||||
capabilities:
|
||||
- create
|
||||
- read
|
||||
- update
|
||||
- delete
|
||||
- list
|
||||
- path: "ghp/roles"
|
||||
capabilities:
|
||||
- read
|
||||
- list
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- tf_vault
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_vault
|
||||
@@ -1,13 +0,0 @@
|
||||
# Lets the agents AppRole mint ephemeral ghp agent tokens, so AI coding agents
|
||||
# authenticate to ghp as their own short-lived, least-privilege identity.
|
||||
# Reading ghp/creds/agent returns a lease-bound token scoped by the role
|
||||
# (token_type agent, contents:read). Mirrors the gitea/creds/unkin-agent binding.
|
||||
---
|
||||
rules:
|
||||
- path: "ghp/creds/agent"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- agents
|
||||
@@ -0,0 +1,17 @@
|
||||
# Allow ghp to read its GitHub App credentials and encryption key
|
||||
#
|
||||
# kv/kubernetes/ghp/github-app (app_id/client_id/client_secret/private_key)
|
||||
# kv/kubernetes/ghp/app (encryption_key)
|
||||
---
|
||||
rules:
|
||||
- path: "kv/data/kubernetes/ghp/*"
|
||||
capabilities:
|
||||
- read
|
||||
- path: "kv/metadata/kubernetes/ghp/*"
|
||||
capabilities:
|
||||
- read
|
||||
- list
|
||||
|
||||
auth:
|
||||
k8s/au/syd1:
|
||||
- ghp
|
||||
@@ -1,22 +0,0 @@
|
||||
# Allow the terraform-vault deployer to read the seeded arrproxy admin token so
|
||||
# the arrstack engine config module can source it. The token is seeded by
|
||||
# argocd-apps #384 at kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token.
|
||||
# The deployer's existing secret_backends_read policy only covers
|
||||
# kv/data/service/vault/+/+/secret_backend/*, which does not match this
|
||||
# kubernetes/namespace path, so this adds the minimal read grant rather than
|
||||
# duplicating the secret into the litellm-style path. vault_kv_secret_v2 also
|
||||
# reads the kv-v2 metadata path on every plan/apply, so grant that too.
|
||||
---
|
||||
rules:
|
||||
- path: "kv/data/kubernetes/namespace/arrstack/default/arrproxy-admin-token"
|
||||
capabilities:
|
||||
- read
|
||||
- path: "kv/metadata/kubernetes/namespace/arrstack/default/arrproxy-admin-token"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- tf_vault
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_vault
|
||||
Reference in New Issue
Block a user