Compare commits
33 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 1dace21b37 | |||
| 9e7687fccb | |||
| 8ccc5f1393 | |||
| 521ef4f0f3 | |||
| d080279728 | |||
| 03dc436a89 | |||
| c20e7e4664 | |||
| aac651a5e4 | |||
| 95927202ba | |||
| d61e985ef2 | |||
| 0e6da5cdd3 | |||
| c0cc74927c | |||
| 31f32aba0f | |||
| 96a6a7d728 | |||
| bf9c785281 | |||
| d82580f1af | |||
| 2c27395613 | |||
| d289775e38 | |||
| 31424ea6ff | |||
| 1fa5900787 | |||
| dcc73131a4 | |||
| 87e3ada14f | |||
| 193c17d1bc | |||
| 03e9baf17f | |||
| b825fdebf7 | |||
| 7da23d47fe | |||
| 933de177fa | |||
| ce1185deba | |||
| 3d59758324 | |||
| 8bb071ae46 | |||
| 0dba5e00a6 | |||
| a400e5dc7e | |||
| 95e7a81b2e |
@@ -7,8 +7,9 @@ steps:
|
||||
image: git.unkin.net/unkin/almalinux9-opentofu:20260606
|
||||
environment:
|
||||
VAULT_AUTH_METHOD: kubernetes
|
||||
VAULT_VERSION: "1.20.0"
|
||||
commands:
|
||||
- dnf install vault -y
|
||||
- curl -fsSL -o /tmp/vault.zip "https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/hashicorp-releases/vault/$${VAULT_VERSION}/vault_$${VAULT_VERSION}_linux_amd64.zip" && python3 -m zipfile -e /tmp/vault.zip /tmp/ && install -m0755 /tmp/vault /usr/local/bin/vault && rm -f /tmp/vault.zip /tmp/vault /tmp/LICENSE.txt
|
||||
- make plan
|
||||
- make apply
|
||||
backend_options:
|
||||
|
||||
@@ -6,8 +6,9 @@ steps:
|
||||
image: git.unkin.net/unkin/almalinux9-opentofu:20260606
|
||||
environment:
|
||||
VAULT_AUTH_METHOD: kubernetes
|
||||
VAULT_VERSION: "1.20.0"
|
||||
commands:
|
||||
- dnf install vault -y
|
||||
- curl -fsSL -o /tmp/vault.zip "https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/hashicorp-releases/vault/$${VAULT_VERSION}/vault_$${VAULT_VERSION}_linux_amd64.zip" && python3 -m zipfile -e /tmp/vault.zip /tmp/ && install -m0755 /tmp/vault /usr/local/bin/vault && rm -f /tmp/vault.zip /tmp/vault /tmp/LICENSE.txt
|
||||
- make plan
|
||||
backend_options:
|
||||
kubernetes:
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
token_ttl: 3600
|
||||
token_max_ttl: 14400
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
use_deterministic_role_id: true
|
||||
@@ -0,0 +1,9 @@
|
||||
token_ttl: 120
|
||||
token_max_ttl: 120
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
- "198.18.25.102/32"
|
||||
- "198.18.26.91/32"
|
||||
- "198.18.27.40/32"
|
||||
use_deterministic_role_id: true
|
||||
@@ -0,0 +1,9 @@
|
||||
token_ttl: 120
|
||||
token_max_ttl: 120
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
- "198.18.25.102/32"
|
||||
- "198.18.26.91/32"
|
||||
- "198.18.27.40/32"
|
||||
use_deterministic_role_id: true
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- ghp
|
||||
bound_service_account_namespaces:
|
||||
- ghp
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: vault
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- logarchiver
|
||||
bound_service_account_namespaces:
|
||||
- logging
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: vault
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- terraform-enc
|
||||
bound_service_account_namespaces:
|
||||
- woodpecker
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: https://kubernetes.default.svc.cluster.local
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- terraform-infra
|
||||
bound_service_account_namespaces:
|
||||
- woodpecker
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: https://kubernetes.default.svc.cluster.local
|
||||
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- terraform-rancher
|
||||
bound_service_account_namespaces:
|
||||
- woodpecker
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: https://kubernetes.default.svc.cluster.local
|
||||
@@ -185,5 +185,86 @@ locals {
|
||||
trimsuffix(basename(file_path), ".yaml") => content
|
||||
if startswith(file_path, "pki_mount_only/")
|
||||
}
|
||||
litellm_secret_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(basename(file_path), ".yaml") => content
|
||||
if startswith(file_path, "litellm_secret_backend/")
|
||||
}
|
||||
litellm_secret_backend_role = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "litellm_secret_backend_role/", ""), ".yaml") => merge(content, {
|
||||
name = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = dirname(replace(file_path, "litellm_secret_backend_role/", ""))
|
||||
})
|
||||
if startswith(file_path, "litellm_secret_backend_role/")
|
||||
}
|
||||
plugins = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(basename(file_path), ".yaml") => merge(content, {
|
||||
name = trimsuffix(basename(file_path), ".yaml")
|
||||
})
|
||||
if startswith(file_path, "plugins/")
|
||||
}
|
||||
gpg_secret_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(basename(file_path), ".yaml") => content
|
||||
if startswith(file_path, "gpg_secret_backend/")
|
||||
}
|
||||
gpg_key = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "gpg_key/", ""), ".yaml") => merge(content, {
|
||||
name = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = dirname(replace(file_path, "gpg_key/", ""))
|
||||
})
|
||||
if startswith(file_path, "gpg_key/")
|
||||
}
|
||||
rancher_secret_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(basename(file_path), ".yaml") => content
|
||||
if startswith(file_path, "rancher_secret_backend/")
|
||||
}
|
||||
rancher_secret_backend_service_account = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "rancher_secret_backend_service_account/", ""), ".yaml") => merge(content, {
|
||||
name = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = dirname(replace(file_path, "rancher_secret_backend_service_account/", ""))
|
||||
})
|
||||
if startswith(file_path, "rancher_secret_backend_service_account/")
|
||||
}
|
||||
rancher_secret_backend_role = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "rancher_secret_backend_role/", ""), ".yaml") => merge(content, {
|
||||
name = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = dirname(replace(file_path, "rancher_secret_backend_role/", ""))
|
||||
})
|
||||
if startswith(file_path, "rancher_secret_backend_role/")
|
||||
}
|
||||
gitea_secret_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(basename(file_path), ".yaml") => content
|
||||
if startswith(file_path, "gitea_secret_backend/")
|
||||
}
|
||||
gitea_secret_backend_role = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "gitea_secret_backend_role/", ""), ".yaml") => merge(content, {
|
||||
name = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = dirname(replace(file_path, "gitea_secret_backend_role/", ""))
|
||||
})
|
||||
if startswith(file_path, "gitea_secret_backend_role/")
|
||||
}
|
||||
netbox_secret_backend = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(basename(file_path), ".yaml") => content
|
||||
if startswith(file_path, "netbox_secret_backend/")
|
||||
}
|
||||
netbox_secret_backend_role = {
|
||||
for file_path, content in local.all_configs :
|
||||
trimsuffix(replace(file_path, "netbox_secret_backend_role/", ""), ".yaml") => merge(content, {
|
||||
name = trimsuffix(basename(file_path), ".yaml")
|
||||
netbox_username = trimsuffix(basename(file_path), ".yaml")
|
||||
backend = dirname(replace(file_path, "netbox_secret_backend_role/", ""))
|
||||
})
|
||||
if startswith(file_path, "netbox_secret_backend_role/")
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
consul_roles:
|
||||
- terraform-enc
|
||||
ttl: 120
|
||||
max_ttl: 300
|
||||
datacenters: []
|
||||
@@ -0,0 +1,5 @@
|
||||
consul_roles:
|
||||
- terraform-infra
|
||||
ttl: 120
|
||||
max_ttl: 300
|
||||
datacenters: []
|
||||
@@ -0,0 +1,5 @@
|
||||
consul_roles:
|
||||
- terraform-rancher
|
||||
ttl: 120
|
||||
max_ttl: 300
|
||||
datacenters: []
|
||||
@@ -0,0 +1,11 @@
|
||||
# Mounts the gitea token secrets engine at "gitea" and writes its config.
|
||||
# The seeded site-admin credentials are sensitive and read from KV, not stored
|
||||
# here:
|
||||
# kv/service/vault/au/syd1/secret_backend/gitea/config
|
||||
# -> keys: admin_username (required), admin_password (required)
|
||||
# Populate that KV path with a purpose-built Gitea site-admin bot (2FA disabled)
|
||||
# BEFORE applying, then run `vault write -f gitea/config/rotate-root` after the
|
||||
# first apply so only Vault holds the admin password.
|
||||
description: "Gitea ephemeral scoped access token engine"
|
||||
gitea_url: "https://git.unkin.net"
|
||||
request_timeout_seconds: 30
|
||||
@@ -0,0 +1,17 @@
|
||||
# Role minting ephemeral tokens for the teabot-implementer bot user.
|
||||
# The implementer clones/pushes code and opens pull requests, so it gets write
|
||||
# on repositories (clone + push + PR create) and write on issues (PR/issue
|
||||
# comments). Read is implied by write. No admin/org/user-write scopes.
|
||||
# read:user is required because tea (and most API clients) validate the login
|
||||
# via GET /api/v1/user, which 403s without it (verified against a minted token).
|
||||
# Reading gitea/creds/teabot-implementer mints a lease-bound token deleted from
|
||||
# Gitea on revoke/expiry.
|
||||
---
|
||||
username: teabot-implementer
|
||||
scopes:
|
||||
- write:repository
|
||||
- write:issue
|
||||
- read:user
|
||||
token_name_prefix: vault-teabot-implementer
|
||||
ttl: 3600 # 1h
|
||||
max_ttl: 14400 # 4h
|
||||
@@ -0,0 +1,17 @@
|
||||
# Role minting ephemeral tokens for the teabot-reviewer bot user.
|
||||
# The reviewer reads code and posts pull-request reviews/comments, so it gets
|
||||
# read on repositories (fetch diffs) and write on issues (PR reviews + issue/PR
|
||||
# comments). No repository-write, admin, org, or user-write scopes.
|
||||
# read:user is required because tea (and most API clients) validate the login
|
||||
# via GET /api/v1/user, which 403s without it (verified against a minted token).
|
||||
# Reading gitea/creds/teabot-reviewer mints a lease-bound token deleted from
|
||||
# Gitea on revoke/expiry.
|
||||
---
|
||||
username: teabot-reviewer
|
||||
scopes:
|
||||
- read:repository
|
||||
- write:issue
|
||||
- read:user
|
||||
token_name_prefix: vault-teabot-reviewer
|
||||
ttl: 3600 # 1h
|
||||
max_ttl: 14400 # 4h
|
||||
@@ -0,0 +1,20 @@
|
||||
# Role minting ephemeral tokens for the unkin-agent bot user -- the shared
|
||||
# identity Ben's AI coding agents use to submit work. The agent clones/pushes
|
||||
# code and opens pull requests, so it gets write on repositories (clone + push +
|
||||
# PR create) and write on issues (PR/issue comments). Read is implied by write.
|
||||
# No admin/org/user-write scopes, so it can never merge via API privilege; merge
|
||||
# is blocked separately by branch protection (merge whitelist = Owners).
|
||||
# read:user is required because tea (and most API clients) validate the login
|
||||
# via GET /api/v1/user, which 403s without it.
|
||||
# Reading gitea/creds/unkin-agent mints a lease-bound token deleted from Gitea
|
||||
# on revoke/expiry. Consumed by the "agents" AppRole (see
|
||||
# policies/gitea/creds/unkin-agent.yaml).
|
||||
---
|
||||
username: unkin-agent
|
||||
scopes:
|
||||
- write:repository
|
||||
- write:issue
|
||||
- read:user
|
||||
token_name_prefix: vault-unkin-agent
|
||||
ttl: 3600 # 1h
|
||||
max_ttl: 14400 # 4h
|
||||
@@ -0,0 +1,8 @@
|
||||
# config/gpg_key/gpg/logarchive.yaml
|
||||
# OpenPGP key in the gpg engine for the logarchiver service. The private key
|
||||
# stays in Vault; logarchiver reads only the exported public key
|
||||
# (gpg/keys/logarchive) to encrypt archived logs, and retrieval delegates
|
||||
# decryption back to gpg/decrypt/logarchive. Key name = "logarchive", backend = "gpg".
|
||||
algorithm: rsa-4096
|
||||
identity: "logarchive <logarchive@unkin.net>"
|
||||
exportable: false
|
||||
@@ -0,0 +1,7 @@
|
||||
# config/gpg_key/gpg/pass.yaml
|
||||
# An OpenPGP key in the gpg engine for password-store (passv). The private key
|
||||
# stays in Vault; clients import the exported public key to encrypt and delegate
|
||||
# decryption to gpg/decrypt/pass. Key name = "pass", backend = "gpg".
|
||||
algorithm: rsa-4096
|
||||
identity: "pass <pass@unkin.net>"
|
||||
exportable: false
|
||||
@@ -0,0 +1,4 @@
|
||||
# config/gpg_secret_backend/gpg.yaml
|
||||
# Mounts the gpg secrets engine at "gpg". The plugin itself is registered in the
|
||||
# catalog separately (see config/plugins/vault-plugin-secrets-gpg.yaml).
|
||||
description: "GPG/OpenPGP secrets engine (sign/verify/encrypt/decrypt)"
|
||||
@@ -0,0 +1,4 @@
|
||||
allowed_kubernetes_namespaces:
|
||||
- "cert-manager"
|
||||
kubernetes_role_type: "Role"
|
||||
extra_labels: {}
|
||||
@@ -0,0 +1,4 @@
|
||||
allowed_kubernetes_namespaces:
|
||||
- "dhcp-system"
|
||||
kubernetes_role_type: "Role"
|
||||
extra_labels: {}
|
||||
@@ -0,0 +1,4 @@
|
||||
allowed_kubernetes_namespaces:
|
||||
- "bind-system"
|
||||
service_account_name: "agent-dns"
|
||||
extra_labels: {}
|
||||
@@ -0,0 +1,4 @@
|
||||
allowed_kubernetes_namespaces:
|
||||
- "cephrgw-system"
|
||||
kubernetes_role_type: "Role"
|
||||
extra_labels: {}
|
||||
@@ -0,0 +1,6 @@
|
||||
# Mounts the LiteLLM dynamic secrets engine at "litellm" and writes its config.
|
||||
# The master key is sensitive and read from KV, not stored here:
|
||||
# kv/service/vault/au/syd1/secret_backend/litellm -> key "master_key"
|
||||
description: "LiteLLM dynamic virtual keys"
|
||||
base_url: "https://litellm.k8s.syd1.au.unkin.net"
|
||||
request_timeout_seconds: 30
|
||||
@@ -0,0 +1,9 @@
|
||||
---
|
||||
models:
|
||||
- claude-opus-4-7
|
||||
max_budget: 5
|
||||
ttl: 3600 # seconds (1h)
|
||||
max_ttl: 86400 # seconds (24h)
|
||||
metadata:
|
||||
team: testuser
|
||||
env: prod
|
||||
@@ -0,0 +1,10 @@
|
||||
---
|
||||
models:
|
||||
- claude-haiku-4-5
|
||||
- claude-sonnet-4-6
|
||||
max_budget: 50
|
||||
ttl: 3600 # seconds (1h)
|
||||
max_ttl: 86400 # seconds (24h)
|
||||
metadata:
|
||||
team: mailfiltering
|
||||
env: prod
|
||||
@@ -0,0 +1,48 @@
|
||||
# Mounts the netbox token secrets engine at "netbox" and writes its config.
|
||||
# The seeded NetBox admin token is sensitive and read from KV, not stored here:
|
||||
# kv/service/vault/au/syd1/secret_backend/netbox/config
|
||||
# -> key: admin_token (required) the SINGLE static admin credential
|
||||
#
|
||||
# admin_token must be a BARE NetBox token with NO scheme prefix: do not prepend
|
||||
# "Bearer " or "Token ". NetBox infers the version from the value's nbt_ prefix,
|
||||
# so one bare token authenticates under either scheme; the plugin adds the keyword
|
||||
# itself. A prefixed value yields a malformed header + 403.
|
||||
#
|
||||
# Populate admin_token with a purpose-built NetBox superuser token (add_user +
|
||||
# add_token + grant_token, or superuser) BEFORE applying, then run
|
||||
# `vault write -f netbox/config/rotate` after the first apply so only Vault holds
|
||||
# the live admin token.
|
||||
#
|
||||
# Only ONE static admin token exists. netbox_user_management does NOT re-read this
|
||||
# token; instead the engine mints it a short-lived user-admin token per apply from
|
||||
# netbox/roles/vault-user-mgmt (see user_mgmt_username below), so rotating
|
||||
# admin_token never breaks user management. Set user_mgmt_username to the
|
||||
# pre-existing NetBox superuser the static admin_token belongs to (or another
|
||||
# superuser). Leaving it unset falls back to using admin_token directly, which is
|
||||
# only a bootstrap/degraded path and breaks after rotation.
|
||||
#
|
||||
# Bootstrap ordering: the vault-user-mgmt role must exist before the netbox
|
||||
# provider is configured from its creds, so on a brand-new backend apply the mount
|
||||
# + role first (e.g. `tofu apply -target=...netbox_secret_backend
|
||||
# -target=...netbox_user_mgmt_role`) once, then apply normally.
|
||||
#
|
||||
# token_version 2 is the NetBox 4.6.5 default and requires API_TOKEN_PEPPERS to
|
||||
# be configured on the NetBox server; set token_version: 1 here if the server
|
||||
# has no peppers. token_version does NOT change how the plugin authenticates its
|
||||
# own calls (that scheme comes from the admin_token value's nbt_ prefix); it only
|
||||
# sets the version of the per-user tokens the engine mints. It must still MATCH
|
||||
# the admin_token kind: nbt_ v2 token -> token_version 2; bare v1 token -> 1.
|
||||
#
|
||||
# The mount uses ignore_changes=[token], so editing KV alone does NOT reach the
|
||||
# live mount. To push a corrected/rotated admin token into a running mount:
|
||||
# vault write netbox/config token=<BARE_TOKEN>
|
||||
# (netbox_url/token_version are preserved on a partial update). Do NOT -replace
|
||||
# the mount to force a re-read - that recreates it and drops all roles/config.
|
||||
description: "NetBox ephemeral scoped API token engine"
|
||||
netbox_url: "https://netbox.k8s.syd1.au.unkin.net"
|
||||
token_version: 2
|
||||
request_timeout_seconds: 30
|
||||
# Set to the pre-existing NetBox superuser admin_token belongs to, to mint the
|
||||
# user-management credential dynamically (recommended). Until set, user management
|
||||
# uses admin_token directly and a check block warns that rotation will break it.
|
||||
# user_mgmt_username: "vault-netbox-admin"
|
||||
@@ -0,0 +1,25 @@
|
||||
# Single declarative source for the terraform-infra NetBox service identity. The
|
||||
# filename stem is the engine role name AND the NetBox username (1:1); config.hcl
|
||||
# derives both from it, so neither is repeated below. Creating this file creates
|
||||
# the user: the netbox_user_management module synthesizes the NetBox user + object
|
||||
# permissions from the permissions block, and the engine role mints ephemeral
|
||||
# tokens for that same user. write_enabled true because terraform-infra manages
|
||||
# NetBox IPAM/DCIM; very short TTLs because a token is minted per plan/apply and
|
||||
# revoked when the run's lease ends.
|
||||
---
|
||||
write_enabled: true
|
||||
ttl: 120 # 2m
|
||||
max_ttl: 300 # 5m
|
||||
permissions:
|
||||
- object_types:
|
||||
- ipam.prefix
|
||||
- ipam.ipaddress
|
||||
- ipam.iprange
|
||||
- dcim.device
|
||||
- dcim.interface
|
||||
- dcim.macaddress
|
||||
actions:
|
||||
- view
|
||||
- add
|
||||
- change
|
||||
- delete
|
||||
@@ -0,0 +1,11 @@
|
||||
# config/plugins/vault-plugin-secrets-gitea.yaml
|
||||
# Imports (registers) the gitea secrets plugin in the catalog. Filename =
|
||||
# catalog name = mount type. The binary is installed on the OpenBao nodes by
|
||||
# Puppet (openbao-plugin-secrets-gitea RPM ->
|
||||
# /opt/openbao-plugins/vault-plugin-secrets-gitea).
|
||||
#
|
||||
# sha256 pins the released v0.1.0 binary; bump it in lockstep with any RPM
|
||||
# upgrade or OpenBao will refuse to launch the plugin.
|
||||
type: secret
|
||||
command: vault-plugin-secrets-gitea
|
||||
sha256: "8f67fbc216effada5fd7399888a710b62fad83be0b31761a439e7dec3d56509b"
|
||||
@@ -0,0 +1,10 @@
|
||||
# config/plugins/vault-plugin-secrets-gpg.yaml
|
||||
# Imports (registers) the gpg secrets plugin in the catalog. Filename = catalog
|
||||
# name = mount type. The binary is installed on the OpenBao nodes by Puppet
|
||||
# (openbao-plugin-secrets-gpg RPM -> /opt/openbao-plugins/vault-plugin-secrets-gpg).
|
||||
#
|
||||
# sha256 pins the released v0.1.0 binary; bump it in lockstep with any RPM
|
||||
# upgrade or OpenBao will refuse to launch the plugin.
|
||||
type: secret
|
||||
command: vault-plugin-secrets-gpg
|
||||
sha256: "0e92d7408795688badb55789bc1604e8f1dd4d71998656c7f831991fce9a7b20"
|
||||
@@ -0,0 +1,13 @@
|
||||
# config/plugins/vault-plugin-secrets-litellm.yaml
|
||||
# Imports (registers) the litellm secrets plugin in the catalog. This plugin was
|
||||
# registered manually before terraform managed the catalog, so its state must be
|
||||
# imported before the first apply (see the PR description) — otherwise apply
|
||||
# tries to create an entry that already exists.
|
||||
#
|
||||
# sha256 is the released v0.1.1 openbao binary
|
||||
# (openbao-plugin-secrets-litellm RPM -> /opt/openbao-plugins/vault-plugin-secrets-litellm),
|
||||
# which Puppet installs floating. Verify against the live catalog during import
|
||||
# (`bao read sys/plugins/catalog/secret/vault-plugin-secrets-litellm`).
|
||||
type: secret
|
||||
command: vault-plugin-secrets-litellm
|
||||
sha256: "2263ebcb3498877a87ddcf31a9cbc6efca6b81702a5faecf7fe7e40200ca7a1f"
|
||||
@@ -0,0 +1,11 @@
|
||||
# config/plugins/vault-plugin-secrets-netbox.yaml
|
||||
# Imports (registers) the netbox secrets plugin in the catalog. Filename =
|
||||
# catalog name = mount type. The binary is installed on the OpenBao nodes by
|
||||
# Puppet (openbao-plugin-secrets-netbox RPM ->
|
||||
# /opt/openbao-plugins/vault-plugin-secrets-netbox).
|
||||
#
|
||||
# sha256 pins the released v0.1.0 binary; bump it in lockstep with any RPM
|
||||
# upgrade or OpenBao will refuse to launch the plugin.
|
||||
type: secret
|
||||
command: vault-plugin-secrets-netbox
|
||||
sha256: "362b7f6c9e21179ad51d2d810684d9387fe50e3a1887f171700122a0b2a05cef"
|
||||
@@ -0,0 +1,11 @@
|
||||
# config/plugins/vault-plugin-secrets-rancher.yaml
|
||||
# Imports (registers) the rancher secrets plugin in the catalog. Filename =
|
||||
# catalog name = mount type. The binary is installed on the OpenBao nodes by
|
||||
# Puppet (openbao-plugin-secrets-rancher RPM ->
|
||||
# /opt/openbao-plugins/vault-plugin-secrets-rancher).
|
||||
#
|
||||
# sha256 pins the released v0.1.1 binary; bump it in lockstep with any RPM
|
||||
# upgrade or OpenBao will refuse to launch the plugin.
|
||||
type: secret
|
||||
command: vault-plugin-secrets-rancher
|
||||
sha256: "9e597cd9512a0629f940141dc6611bf95eaf165abcb52470eee027bf467d5955"
|
||||
@@ -0,0 +1,8 @@
|
||||
# Mounts the rancher token secrets engine at "rancher" and writes its config.
|
||||
# The plugin is registered in the catalog separately (see
|
||||
# config/plugins/vault-plugin-secrets-rancher.yaml). Seeded service-account
|
||||
# tokens live under config/rancher_secret_backend_service_account/rancher/ and
|
||||
# roles under config/rancher_secret_backend_role/rancher/.
|
||||
description: "Rancher API token engine (seeded root rotation + dynamic scoped creds)"
|
||||
rancher_url: "https://rancher.k8s.syd1.au.unkin.net"
|
||||
request_timeout_seconds: 30
|
||||
@@ -0,0 +1,9 @@
|
||||
# A role that mints short-lived Rancher tokens from the "admin" service account.
|
||||
# Reading rancher/creds/ci returns a lease-bound token deleted from Rancher on
|
||||
# revoke. Minted tokens inherit the admin service account's RBAC; only cluster
|
||||
# and TTL are scoped per-token.
|
||||
---
|
||||
service_account: admin
|
||||
description: "CI/CD ephemeral Rancher token"
|
||||
ttl: 3600 # seconds (1h)
|
||||
max_ttl: 28800 # seconds (8h)
|
||||
@@ -0,0 +1,8 @@
|
||||
# A seeded, auto-rotated Rancher service-account token on the "rancher" engine.
|
||||
# The seed token itself is sensitive and read from KV (not stored here):
|
||||
# kv/service/vault/au/syd1/secret_backend/rancher/service_account/admin
|
||||
# -> keys: token (required), token_name (optional)
|
||||
# Populate that KV path with a live Rancher admin token BEFORE applying; the
|
||||
# engine then rotates it (mints a fresh 90d token every 45d) so it never lapses.
|
||||
token_ttl: 7776000 # 90d in seconds
|
||||
rotation_period: 3888000 # 45d in seconds
|
||||
@@ -39,6 +39,12 @@ locals {
|
||||
for backend_name, _ in local.config.consul_secret_backend :
|
||||
backend_name => replace(backend_name, "/", "_")
|
||||
}
|
||||
|
||||
# Same sanitized alias mapping for the NetBox providers.
|
||||
netbox_backend_aliases = {
|
||||
for backend_name, _ in local.config.netbox_secret_backend :
|
||||
backend_name => replace(backend_name, "/", "_")
|
||||
}
|
||||
}
|
||||
|
||||
terraform {
|
||||
@@ -68,6 +74,21 @@ inputs = {
|
||||
kubernetes_secret_backend = local.config.kubernetes_secret_backend
|
||||
kubernetes_secret_backend_role = local.config.kubernetes_secret_backend_role
|
||||
pki_mount_only = local.config.pki_mount_only
|
||||
litellm_secret_backend = local.config.litellm_secret_backend
|
||||
litellm_secret_backend_role = local.config.litellm_secret_backend_role
|
||||
plugins = local.config.plugins
|
||||
gpg_secret_backend = local.config.gpg_secret_backend
|
||||
gpg_key = local.config.gpg_key
|
||||
|
||||
rancher_secret_backend = local.config.rancher_secret_backend
|
||||
rancher_secret_backend_service_account = local.config.rancher_secret_backend_service_account
|
||||
rancher_secret_backend_role = local.config.rancher_secret_backend_role
|
||||
|
||||
gitea_secret_backend = local.config.gitea_secret_backend
|
||||
gitea_secret_backend_role = local.config.gitea_secret_backend_role
|
||||
|
||||
netbox_secret_backend = local.config.netbox_secret_backend
|
||||
netbox_secret_backend_role = local.config.netbox_secret_backend_role
|
||||
|
||||
# Pass policy maps to vault_cluster module
|
||||
policy_auth_map = local.policies.policy_auth_map
|
||||
@@ -75,4 +96,7 @@ inputs = {
|
||||
|
||||
# Pass sanitized consul backend aliases for provider configuration
|
||||
consul_backend_aliases = local.consul_backend_aliases
|
||||
|
||||
# Pass sanitized netbox backend aliases for provider configuration
|
||||
netbox_backend_aliases = local.netbox_backend_aliases
|
||||
}
|
||||
|
||||
@@ -11,6 +11,24 @@ provider "vault" {
|
||||
address = local.vault_addr
|
||||
}
|
||||
|
||||
# The LiteLLM secrets engine is managed through its own provider, which talks to
|
||||
# the same Vault server. Token falls back to the VAULT_TOKEN environment variable.
|
||||
provider "litellm" {
|
||||
address = local.vault_addr
|
||||
}
|
||||
|
||||
# The gpg secrets engine's keys are managed through its own provider (same Vault
|
||||
# server; token falls back to VAULT_TOKEN).
|
||||
provider "gpg" {
|
||||
address = local.vault_addr
|
||||
}
|
||||
|
||||
# The rancher token secrets engine is managed through its own provider (same
|
||||
# Vault server; token falls back to VAULT_TOKEN).
|
||||
provider "rancher" {
|
||||
address = local.vault_addr
|
||||
}
|
||||
|
||||
terraform {
|
||||
backend "consul" {
|
||||
address = "https://consul.service.consul"
|
||||
@@ -29,6 +47,18 @@ terraform {
|
||||
source = "hashicorp/consul"
|
||||
version = "2.23.0"
|
||||
}
|
||||
litellm = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/litellmvaultsecret"
|
||||
version = "0.1.0"
|
||||
}
|
||||
gpg = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/gpgvaultsecret"
|
||||
version = "0.1.0"
|
||||
}
|
||||
rancher = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/ranchervaultsecret"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
EOF
|
||||
|
||||
@@ -299,10 +299,243 @@ module "kubernetes_secret_backend_role" {
|
||||
allowed_kubernetes_namespaces = each.value.allowed_kubernetes_namespaces
|
||||
kubernetes_role_type = each.value.kubernetes_role_type
|
||||
extra_labels = each.value.extra_labels
|
||||
service_account_name = each.value.service_account_name
|
||||
|
||||
depends_on = [module.kubernetes_secret_backend]
|
||||
}
|
||||
|
||||
module "litellm_secret_backend" {
|
||||
source = "./modules/litellm_secret_backend"
|
||||
|
||||
for_each = var.litellm_secret_backend
|
||||
|
||||
country = var.country
|
||||
region = var.region
|
||||
path = each.key
|
||||
plugin = each.value.plugin
|
||||
description = each.value.description
|
||||
base_url = each.value.base_url
|
||||
request_timeout_seconds = each.value.request_timeout_seconds
|
||||
}
|
||||
|
||||
module "litellm_secret_backend_role" {
|
||||
source = "./modules/litellm_secret_backend_role"
|
||||
|
||||
for_each = var.litellm_secret_backend_role
|
||||
|
||||
name = each.value.name
|
||||
backend = each.value.backend
|
||||
models = each.value.models
|
||||
max_budget = each.value.max_budget
|
||||
key_alias_prefix = each.value.key_alias_prefix
|
||||
ttl = each.value.ttl
|
||||
max_ttl = each.value.max_ttl
|
||||
metadata = each.value.metadata
|
||||
|
||||
depends_on = [module.litellm_secret_backend]
|
||||
}
|
||||
|
||||
module "plugin" {
|
||||
source = "./modules/plugin"
|
||||
|
||||
for_each = var.plugins
|
||||
|
||||
name = each.value.name
|
||||
type = each.value.type
|
||||
command = each.value.command
|
||||
sha256 = each.value.sha256
|
||||
plugin_version = each.value.version
|
||||
}
|
||||
|
||||
module "gpg_secret_backend" {
|
||||
source = "./modules/gpg_secret_backend"
|
||||
|
||||
for_each = var.gpg_secret_backend
|
||||
|
||||
path = each.key
|
||||
plugin = each.value.plugin
|
||||
description = each.value.description
|
||||
|
||||
depends_on = [module.plugin]
|
||||
}
|
||||
|
||||
module "gpg_key" {
|
||||
source = "./modules/gpg_key"
|
||||
|
||||
for_each = var.gpg_key
|
||||
|
||||
backend = each.value.backend
|
||||
name = each.value.name
|
||||
algorithm = each.value.algorithm
|
||||
identity = each.value.identity
|
||||
exportable = each.value.exportable
|
||||
deletion_allowed = each.value.deletion_allowed
|
||||
min_decryption_version = each.value.min_decryption_version
|
||||
|
||||
depends_on = [module.gpg_secret_backend]
|
||||
}
|
||||
|
||||
module "rancher_secret_backend" {
|
||||
source = "./modules/rancher_secret_backend"
|
||||
|
||||
for_each = var.rancher_secret_backend
|
||||
|
||||
path = each.key
|
||||
plugin = each.value.plugin
|
||||
description = each.value.description
|
||||
rancher_url = each.value.rancher_url
|
||||
ca_cert = each.value.ca_cert
|
||||
tls_skip_verify = each.value.tls_skip_verify
|
||||
request_timeout_seconds = each.value.request_timeout_seconds
|
||||
|
||||
depends_on = [module.plugin]
|
||||
}
|
||||
|
||||
module "rancher_secret_backend_service_account" {
|
||||
source = "./modules/rancher_secret_backend_service_account"
|
||||
|
||||
for_each = var.rancher_secret_backend_service_account
|
||||
|
||||
backend = each.value.backend
|
||||
name = each.value.name
|
||||
country = var.country
|
||||
region = var.region
|
||||
token_ttl = each.value.token_ttl
|
||||
rotation_period = each.value.rotation_period
|
||||
|
||||
depends_on = [module.rancher_secret_backend]
|
||||
}
|
||||
|
||||
module "rancher_secret_backend_role" {
|
||||
source = "./modules/rancher_secret_backend_role"
|
||||
|
||||
for_each = var.rancher_secret_backend_role
|
||||
|
||||
backend = each.value.backend
|
||||
name = each.value.name
|
||||
service_account = each.value.service_account
|
||||
cluster_name = each.value.cluster_name
|
||||
description = each.value.description
|
||||
ttl = each.value.ttl
|
||||
max_ttl = each.value.max_ttl
|
||||
|
||||
depends_on = [module.rancher_secret_backend_service_account]
|
||||
}
|
||||
|
||||
module "gitea_secret_backend" {
|
||||
source = "./modules/gitea_secret_backend"
|
||||
|
||||
for_each = var.gitea_secret_backend
|
||||
|
||||
path = each.key
|
||||
plugin = each.value.plugin
|
||||
description = each.value.description
|
||||
gitea_url = each.value.gitea_url
|
||||
country = var.country
|
||||
region = var.region
|
||||
ca_cert = each.value.ca_cert
|
||||
tls_skip_verify = each.value.tls_skip_verify
|
||||
request_timeout_seconds = each.value.request_timeout_seconds
|
||||
|
||||
depends_on = [module.plugin]
|
||||
}
|
||||
|
||||
module "gitea_secret_backend_role" {
|
||||
source = "./modules/gitea_secret_backend_role"
|
||||
|
||||
for_each = var.gitea_secret_backend_role
|
||||
|
||||
backend = each.value.backend
|
||||
name = each.value.name
|
||||
username = each.value.username
|
||||
scopes = each.value.scopes
|
||||
token_name_prefix = each.value.token_name_prefix
|
||||
ttl = each.value.ttl
|
||||
max_ttl = each.value.max_ttl
|
||||
|
||||
depends_on = [module.gitea_secret_backend]
|
||||
}
|
||||
|
||||
module "netbox_secret_backend" {
|
||||
source = "./modules/netbox_secret_backend"
|
||||
|
||||
for_each = var.netbox_secret_backend
|
||||
|
||||
path = each.key
|
||||
plugin = each.value.plugin
|
||||
description = each.value.description
|
||||
netbox_url = each.value.netbox_url
|
||||
token_version = each.value.token_version
|
||||
country = var.country
|
||||
region = var.region
|
||||
ca_cert = each.value.ca_cert
|
||||
tls_skip_verify = each.value.tls_skip_verify
|
||||
request_timeout_seconds = each.value.request_timeout_seconds
|
||||
|
||||
depends_on = [module.plugin]
|
||||
}
|
||||
|
||||
# Dedicated engine role that mints an ephemeral, user-admin-capable token for the
|
||||
# pre-existing NetBox superuser named on each backend (user_mgmt_username).
|
||||
# netbox_user_management reads netbox/creds/vault-user-mgmt from it, so it
|
||||
# authenticates with a short-lived Vault-minted token derived from the single
|
||||
# static admin token - never a second static credential, and unaffected by
|
||||
# rotation of the engine's admin seed. Created before user management so the role
|
||||
# exists when it reads creds.
|
||||
module "netbox_user_mgmt_role" {
|
||||
source = "./modules/netbox_secret_backend_role"
|
||||
|
||||
for_each = { for k, v in var.netbox_secret_backend : k => v if v.user_mgmt_username != null }
|
||||
|
||||
backend = each.key
|
||||
name = "vault-user-mgmt"
|
||||
netbox_username = each.value.user_mgmt_username
|
||||
write_enabled = true
|
||||
description = "Ephemeral user-admin token for netbox_user_management (Vault-minted per apply)"
|
||||
ttl = 600
|
||||
max_ttl = 1200
|
||||
|
||||
depends_on = [module.netbox_secret_backend]
|
||||
}
|
||||
|
||||
# Declaratively manage the NetBox service users + object permissions the engine
|
||||
# roles mint tokens for, authenticating with the Vault-minted user-admin token
|
||||
# above (mirrors consul_acl_management). Consumes the SAME role config as
|
||||
# netbox_secret_backend_role: one file per identity, filename-derived username,
|
||||
# inline permissions.
|
||||
module "netbox_user_management" {
|
||||
source = "./modules/netbox_user_management"
|
||||
|
||||
country = var.country
|
||||
region = var.region
|
||||
netbox_backends = var.netbox_secret_backend
|
||||
netbox_roles = var.netbox_secret_backend_role
|
||||
netbox_backend_aliases = var.netbox_backend_aliases
|
||||
|
||||
# This module declares its own netbox provider, so it is a legacy module and
|
||||
# cannot take depends_on. Ordering vs the vault-user-mgmt role is not needed on
|
||||
# steady state (the role pre-exists, so reading its creds succeeds regardless);
|
||||
# on first enablement the role must be created first via the one-time targeted
|
||||
# bootstrap documented in config/netbox_secret_backend/netbox.yaml.
|
||||
}
|
||||
|
||||
module "netbox_secret_backend_role" {
|
||||
source = "./modules/netbox_secret_backend_role"
|
||||
|
||||
for_each = var.netbox_secret_backend_role
|
||||
|
||||
backend = each.value.backend
|
||||
name = each.value.name
|
||||
netbox_username = each.value.netbox_username
|
||||
netbox_user_id = each.value.netbox_user_id
|
||||
write_enabled = each.value.write_enabled
|
||||
description = each.value.description
|
||||
ttl = each.value.ttl
|
||||
max_ttl = each.value.max_ttl
|
||||
|
||||
depends_on = [module.netbox_secret_backend, module.netbox_user_management]
|
||||
}
|
||||
|
||||
module "vault_policy" {
|
||||
source = "./modules/vault_policy"
|
||||
|
||||
|
||||
@@ -0,0 +1,34 @@
|
||||
# Mounts the gitea secrets engine and writes its connection config via the
|
||||
# giteavaultsecret provider. The plugin is registered ("imported") in the
|
||||
# catalog separately (config/plugins/vault-plugin-secrets-gitea.yaml). The
|
||||
# seeded site-admin credentials are sensitive and read from KV, not stored in
|
||||
# git:
|
||||
# kv/service/vault/<country>/<region>/secret_backend/<path>/config
|
||||
# Expected keys: admin_username (required), admin_password (required).
|
||||
data "vault_kv_secret_v2" "config" {
|
||||
mount = "kv"
|
||||
name = "service/vault/${var.country}/${var.region}/secret_backend/${var.path}/config"
|
||||
}
|
||||
|
||||
resource "gitea_secret_backend" "this" {
|
||||
path = var.path
|
||||
plugin = var.plugin
|
||||
description = var.description
|
||||
gitea_url = var.gitea_url
|
||||
admin_username = data.vault_kv_secret_v2.config.data["admin_username"]
|
||||
admin_password = data.vault_kv_secret_v2.config.data["admin_password"]
|
||||
ca_cert = var.ca_cert
|
||||
tls_skip_verify = var.tls_skip_verify
|
||||
request_timeout_seconds = var.request_timeout_seconds
|
||||
|
||||
lifecycle {
|
||||
# The KV seed is a bootstrap credential: it is consumed only when the engine
|
||||
# config is first created. After creation the live admin password is rotated
|
||||
# in place (vault write -f gitea/config/rotate-root) and diverges from the
|
||||
# seed, so re-reading the (possibly stale) KV value must never push it back.
|
||||
# Ignoring the credential attributes makes this module create-only for them.
|
||||
# (The sibling rancher/litellm seed modules do not yet do this and would
|
||||
# re-push their seed on a subsequent apply.)
|
||||
ignore_changes = [admin_username, admin_password]
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
vault = {
|
||||
source = "hashicorp/vault"
|
||||
version = "5.6.0"
|
||||
}
|
||||
gitea = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/giteavaultsecret"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,49 @@
|
||||
variable "path" {
|
||||
description = "Mount path of the gitea secrets engine (e.g. \"gitea\")"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "plugin" {
|
||||
description = "Registered plugin name to mount (the catalog name = mount type)"
|
||||
type = string
|
||||
default = "vault-plugin-secrets-gitea"
|
||||
}
|
||||
|
||||
variable "description" {
|
||||
description = "Human-friendly description of the mount"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "gitea_url" {
|
||||
description = "Base URL of the Gitea server (e.g. https://git.unkin.net)"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "country" {
|
||||
description = "Country segment of the KV path holding the seeded admin credentials"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "region" {
|
||||
description = "Region segment of the KV path holding the seeded admin credentials"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "ca_cert" {
|
||||
description = "PEM CA certificate that signed the Gitea server's TLS cert (optional; omit to use the system trust store)"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "tls_skip_verify" {
|
||||
description = "Skip TLS verification of the Gitea server (not recommended)"
|
||||
type = bool
|
||||
default = false
|
||||
}
|
||||
|
||||
variable "request_timeout_seconds" {
|
||||
description = "HTTP timeout in seconds for calls from the plugin to Gitea"
|
||||
type = number
|
||||
default = 30
|
||||
}
|
||||
@@ -0,0 +1,12 @@
|
||||
# A role that mints short-lived, scoped gitea tokens for a target Gitea user.
|
||||
# Reading gitea/creds/<name> produces a lease-bound token that is deleted from
|
||||
# Gitea when the lease is revoked or reaches max_ttl.
|
||||
resource "gitea_secret_backend_role" "this" {
|
||||
backend = var.backend
|
||||
name = var.name
|
||||
username = var.username
|
||||
scopes = var.scopes
|
||||
token_name_prefix = var.token_name_prefix
|
||||
ttl = var.ttl
|
||||
max_ttl = var.max_ttl
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
gitea = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/giteavaultsecret"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,37 @@
|
||||
variable "backend" {
|
||||
description = "Mount path of the gitea secrets engine this role belongs to"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "name" {
|
||||
description = "Role name (read gitea/creds/<name> to mint a token)"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "username" {
|
||||
description = "Target Gitea username the minted tokens belong to"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "scopes" {
|
||||
description = "Gitea access-token scopes granted to minted tokens (write: implies read:)"
|
||||
type = list(string)
|
||||
}
|
||||
|
||||
variable "token_name_prefix" {
|
||||
description = "Prefix for the generated Gitea token name (optional)"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "ttl" {
|
||||
description = "Default lease TTL in seconds for minted tokens"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "max_ttl" {
|
||||
description = "Maximum lease TTL in seconds for minted tokens"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
@@ -0,0 +1,12 @@
|
||||
# Manages an OpenPGP key inside a gpg secrets engine mount, via the
|
||||
# gpgvaultsecret provider. The private key never leaves Vault; consumers use the
|
||||
# exported public_key to encrypt and delegate decryption back to the engine.
|
||||
resource "gpg_key" "this" {
|
||||
backend = var.backend
|
||||
name = var.name
|
||||
algorithm = var.algorithm
|
||||
identity = var.identity
|
||||
exportable = var.exportable
|
||||
deletion_allowed = var.deletion_allowed
|
||||
min_decryption_version = var.min_decryption_version
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
gpg = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/gpgvaultsecret"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
variable "backend" {
|
||||
description = "Mount path of the gpg secrets engine (e.g. \"gpg\")"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "name" {
|
||||
description = "Name of the key"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "algorithm" {
|
||||
description = "Key algorithm: rsa-2048, rsa-3072, rsa-4096 or ed25519"
|
||||
type = string
|
||||
default = "rsa-3072"
|
||||
}
|
||||
|
||||
variable "identity" {
|
||||
description = "OpenPGP User ID (defaults to the key name)"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "exportable" {
|
||||
description = "Allow exporting the private key (enable-only)"
|
||||
type = bool
|
||||
default = false
|
||||
}
|
||||
|
||||
variable "deletion_allowed" {
|
||||
description = "Whether the key may be deleted"
|
||||
type = bool
|
||||
default = false
|
||||
}
|
||||
|
||||
variable "min_decryption_version" {
|
||||
description = "Minimum key version usable for decryption/verification"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
@@ -0,0 +1,8 @@
|
||||
# Mounts the gpg secrets engine. The plugin is registered ("imported") in the
|
||||
# catalog separately via the config/plugins/ discovery and the plugin module;
|
||||
# this module just enables a mount of the already-registered plugin type.
|
||||
resource "vault_mount" "this" {
|
||||
path = var.path
|
||||
type = var.plugin
|
||||
description = var.description
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
vault = {
|
||||
source = "hashicorp/vault"
|
||||
version = "5.6.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,16 @@
|
||||
variable "path" {
|
||||
description = "Mount path of the GPG secrets engine (e.g. \"gpg\")"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "plugin" {
|
||||
description = "Registered plugin name to mount (the catalog name = mount type)"
|
||||
type = string
|
||||
default = "vault-plugin-secrets-gpg"
|
||||
}
|
||||
|
||||
variable "description" {
|
||||
description = "Human-friendly description of the mount"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
@@ -2,6 +2,10 @@ locals {
|
||||
# Auto-generate role rules path: resources/secret_backend/{backend_path}/roles/{role_name}.yaml
|
||||
role_rules_file = "resources/secret_backend/${var.backend}/roles/${var.name}.yaml"
|
||||
|
||||
# service_account_name mode mints tokens for a pre-existing SA, so the
|
||||
# generated_role_rules / kubernetes_role_type binding fields must be unset.
|
||||
use_service_account = var.service_account_name != null
|
||||
|
||||
# Auto-generate extra labels based on country/region and role name
|
||||
auto_labels = merge(var.extra_labels, {
|
||||
vault-region = "${var.country}-${var.region}"
|
||||
@@ -13,7 +17,8 @@ resource "vault_kubernetes_secret_backend_role" "role" {
|
||||
backend = var.backend
|
||||
name = var.name
|
||||
allowed_kubernetes_namespaces = var.allowed_kubernetes_namespaces
|
||||
kubernetes_role_type = var.kubernetes_role_type
|
||||
generated_role_rules = file("${path.module}/../../../../../../../../${local.role_rules_file}")
|
||||
kubernetes_role_type = local.use_service_account ? null : var.kubernetes_role_type
|
||||
generated_role_rules = local.use_service_account ? null : file("${path.module}/../../../../../../../../${local.role_rules_file}")
|
||||
service_account_name = var.service_account_name
|
||||
extra_labels = local.auto_labels
|
||||
}
|
||||
|
||||
@@ -34,4 +34,10 @@ variable "extra_labels" {
|
||||
description = "Additional labels to apply to generated Kubernetes objects"
|
||||
type = map(string)
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "service_account_name" {
|
||||
description = "Pre-existing service account to mint tokens for. When set, RBAC comes from that SA's own bindings instead of generated_role_rules."
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
@@ -0,0 +1,14 @@
|
||||
# Expected keys in KV secret: master_key
|
||||
data "vault_kv_secret_v2" "secret_backend_config" {
|
||||
mount = "kv"
|
||||
name = "service/vault/${var.country}/${var.region}/secret_backend/${var.path}"
|
||||
}
|
||||
|
||||
resource "litellm_secret_backend" "this" {
|
||||
path = var.path
|
||||
plugin = var.plugin
|
||||
description = var.description
|
||||
base_url = var.base_url
|
||||
master_key = data.vault_kv_secret_v2.secret_backend_config.data["master_key"]
|
||||
request_timeout_seconds = var.request_timeout_seconds
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
vault = {
|
||||
source = "hashicorp/vault"
|
||||
version = "5.6.0"
|
||||
}
|
||||
litellm = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/litellmvaultsecret"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,37 @@
|
||||
variable "country" {
|
||||
description = "Country identifier (used to locate the KV secret holding the master key)"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "region" {
|
||||
description = "Region identifier (used to locate the KV secret holding the master key)"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "path" {
|
||||
description = "Mount path of the LiteLLM secrets engine"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "plugin" {
|
||||
description = "Registered plugin name/type to mount"
|
||||
type = string
|
||||
default = "vault-plugin-secrets-litellm"
|
||||
}
|
||||
|
||||
variable "description" {
|
||||
description = "Human-friendly description of the mount"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "base_url" {
|
||||
description = "Base URL of the LiteLLM proxy (e.g. http://litellm.litellm.svc:4000)"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "request_timeout_seconds" {
|
||||
description = "HTTP timeout in seconds for calls from the plugin to the LiteLLM proxy"
|
||||
type = number
|
||||
default = 30
|
||||
}
|
||||
@@ -0,0 +1,10 @@
|
||||
resource "litellm_secret_backend_role" "this" {
|
||||
backend = var.backend
|
||||
name = var.name
|
||||
models = var.models
|
||||
max_budget = var.max_budget
|
||||
key_alias_prefix = var.key_alias_prefix
|
||||
ttl = var.ttl
|
||||
max_ttl = var.max_ttl
|
||||
metadata = var.metadata
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
litellm = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/litellmvaultsecret"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,45 @@
|
||||
variable "name" {
|
||||
description = "Name of the role"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "backend" {
|
||||
description = "Mount path of the LiteLLM secrets engine this role belongs to"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "models" {
|
||||
description = "Models a generated key may access. Empty means unrestricted"
|
||||
type = list(string)
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "max_budget" {
|
||||
description = "Spending limit applied to each generated key. 0 means unlimited"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "key_alias_prefix" {
|
||||
description = "Prefix for the auto-generated key alias"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "ttl" {
|
||||
description = "Default lease TTL in seconds for keys generated from this role"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "max_ttl" {
|
||||
description = "Maximum lease TTL in seconds for keys generated from this role"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "metadata" {
|
||||
description = "Metadata attached to each generated key"
|
||||
type = map(string)
|
||||
default = null
|
||||
}
|
||||
@@ -0,0 +1,53 @@
|
||||
# Mounts the netbox secrets engine and writes its connection config via the
|
||||
# vault-secrets-netbox provider. The plugin is registered ("imported") in the
|
||||
# catalog separately (config/plugins/vault-plugin-secrets-netbox.yaml). The
|
||||
# seeded NetBox admin token is sensitive and read from KV, not stored in git:
|
||||
# kv/service/vault/<country>/<region>/secret_backend/<path>/config
|
||||
# Expected key: admin_token (a NetBox token with add_token + grant_token, i.e.
|
||||
# able to provision and delegate per-user API tokens).
|
||||
data "vault_kv_secret_v2" "config" {
|
||||
mount = "kv"
|
||||
name = "service/vault/${var.country}/${var.region}/secret_backend/${var.path}/config"
|
||||
|
||||
lifecycle {
|
||||
# The plugin builds its own Authorization header from the token VALUE, not
|
||||
# token_version: a value starting with the nbt_ prefix is sent as
|
||||
# "Bearer <token>" (v2), otherwise "Token <token>" (v1). So admin_token must
|
||||
# be the BARE token - a literal `Bearer `/`Token ` scheme prefix yields a
|
||||
# malformed three-part header and 403s on the plugin's own NetBox calls.
|
||||
#
|
||||
# token_version does NOT change that header; it only selects the version of
|
||||
# the per-user tokens the engine mints for roles. It must still MATCH the
|
||||
# admin token's kind so the mount and its minted creds line up: an nbt_ v2
|
||||
# admin token pairs with token_version=2, a bare v1 token with token_version=1.
|
||||
postcondition {
|
||||
condition = nonsensitive(
|
||||
!startswith(self.data["admin_token"], "Bearer ") &&
|
||||
!startswith(self.data["admin_token"], "Token ") &&
|
||||
startswith(self.data["admin_token"], "nbt_") == (var.token_version == 2)
|
||||
)
|
||||
error_message = "KV admin_token for netbox backend '${var.path}' must be a BARE NetBox token with no 'Bearer '/'Token ' scheme prefix, AND its version must match token_version: a v2 token (nbt_<key>.<secret>) requires token_version=2; a v1 token (bare 40-char value) requires token_version=1."
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "netbox_secret_backend" "this" {
|
||||
path = var.path
|
||||
plugin = var.plugin
|
||||
description = var.description
|
||||
netbox_url = var.netbox_url
|
||||
token = data.vault_kv_secret_v2.config.data["admin_token"]
|
||||
token_version = var.token_version
|
||||
ca_cert = var.ca_cert
|
||||
tls_skip_verify = var.tls_skip_verify
|
||||
request_timeout_seconds = var.request_timeout_seconds
|
||||
|
||||
lifecycle {
|
||||
# The KV seed is a bootstrap credential: it is consumed only when the engine
|
||||
# config is first created. After creation the live admin token is rotated in
|
||||
# place (vault write -f netbox/config/rotate) and diverges from the seed, so
|
||||
# re-reading the (possibly stale) KV value must never push it back. Ignoring
|
||||
# the token makes this module create-only for it (mirrors gitea/config).
|
||||
ignore_changes = [token]
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
vault = {
|
||||
source = "hashicorp/vault"
|
||||
version = "5.6.0"
|
||||
}
|
||||
netbox = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/vault-secrets-netbox"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,55 @@
|
||||
variable "path" {
|
||||
description = "Mount path of the netbox secrets engine (e.g. \"netbox\")"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "plugin" {
|
||||
description = "Registered plugin name to mount (the catalog name = mount type)"
|
||||
type = string
|
||||
default = "vault-plugin-secrets-netbox"
|
||||
}
|
||||
|
||||
variable "description" {
|
||||
description = "Human-friendly description of the mount"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "netbox_url" {
|
||||
description = "Base URL of the NetBox server (e.g. https://netbox.k8s.syd1.au.unkin.net)"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "token_version" {
|
||||
description = "NetBox API token format: 2 (default, requires API_TOKEN_PEPPERS on the NetBox server) or 1 (legacy plaintext-key)."
|
||||
type = number
|
||||
default = 2
|
||||
}
|
||||
|
||||
variable "country" {
|
||||
description = "Country segment of the KV path holding the seeded admin token"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "region" {
|
||||
description = "Region segment of the KV path holding the seeded admin token"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "ca_cert" {
|
||||
description = "PEM CA certificate that signed the NetBox server's TLS cert (optional; omit to use the system trust store)"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "tls_skip_verify" {
|
||||
description = "Skip TLS verification of the NetBox server (not recommended)"
|
||||
type = bool
|
||||
default = false
|
||||
}
|
||||
|
||||
variable "request_timeout_seconds" {
|
||||
description = "HTTP timeout in seconds for calls from the plugin to NetBox"
|
||||
type = number
|
||||
default = 30
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
# A role that mints short-lived, scoped NetBox tokens for a pre-existing NetBox
|
||||
# service user. Reading netbox/creds/<name> produces a lease-bound token that is
|
||||
# deleted from NetBox when the lease is revoked or reaches max_ttl.
|
||||
resource "netbox_secret_backend_role" "this" {
|
||||
backend = var.backend
|
||||
name = var.name
|
||||
netbox_username = var.netbox_username
|
||||
netbox_user_id = var.netbox_user_id
|
||||
write_enabled = var.write_enabled
|
||||
description = var.description
|
||||
ttl = var.ttl
|
||||
max_ttl = var.max_ttl
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
netbox = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/vault-secrets-netbox"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,45 @@
|
||||
variable "backend" {
|
||||
description = "Mount path of the netbox secrets engine this role belongs to"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "name" {
|
||||
description = "Role name (read netbox/creds/<name> to mint a token)"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "netbox_username" {
|
||||
description = "NetBox service username the minted tokens belong to (set this or netbox_user_id)"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "netbox_user_id" {
|
||||
description = "NetBox service user id the minted tokens belong to (set this or netbox_username)"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "write_enabled" {
|
||||
description = "Whether minted tokens carry NetBox write access (default read-only)"
|
||||
type = bool
|
||||
default = false
|
||||
}
|
||||
|
||||
variable "description" {
|
||||
description = "Human-friendly description of the role"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "ttl" {
|
||||
description = "Default lease TTL in seconds for minted tokens (the token's NetBox expiry is aligned to the lease)"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "max_ttl" {
|
||||
description = "Maximum lease TTL in seconds for minted tokens"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
@@ -0,0 +1,7 @@
|
||||
rule "terraform_required_providers" {
|
||||
enabled = false
|
||||
}
|
||||
|
||||
rule "terraform_required_version" {
|
||||
enabled = false
|
||||
}
|
||||
@@ -0,0 +1,149 @@
|
||||
# netbox_user_management reconciles NetBox service users + permissions on every
|
||||
# apply, so it needs an admin credential each run. That credential is minted
|
||||
# DYNAMICALLY by the netbox engine from the SINGLE static admin token, so no
|
||||
# second static credential exists and it survives rotation of the engine seed:
|
||||
#
|
||||
# 1. module.netbox_user_mgmt_role creates netbox/roles/vault-user-mgmt, a
|
||||
# write-enabled role for a pre-existing NetBox superuser (user_mgmt_username).
|
||||
# 2. Reading netbox/creds/vault-user-mgmt mints a short-lived, user-admin-capable
|
||||
# token for that superuser; the e-breuninger provider uses it to CRUD users.
|
||||
#
|
||||
# The hashicorp/vault provider ships ephemeral resources for KV only, not for
|
||||
# dynamic engine creds, so the mint is read via the vault_generic_secret DATA
|
||||
# source: the short-lived token transits Terraform state (sensitive, lease-revoked)
|
||||
# and is re-minted each plan. This is the closest single-static-token shape the
|
||||
# current providers allow; move to an ephemeral resource once the vault provider
|
||||
# ships a dynamic-secret one. Ordering note: the vault-user-mgmt role must already
|
||||
# exist when this reads creds, so on a brand-new backend bootstrap the mount +
|
||||
# role first (targeted apply) - a fresh single apply cannot configure the netbox
|
||||
# provider from a role created in the same run.
|
||||
locals {
|
||||
# Backends that mint a dynamic user-admin token (a pre-existing superuser named).
|
||||
netbox_dynamic_backends = { for k, v in var.netbox_backends : k => v if v.user_mgmt_username != null }
|
||||
# Backends still using the single static admin_token directly (until a superuser
|
||||
# is named). Bootstrap/degraded path - the same one token, not a second static.
|
||||
netbox_static_backends = { for k, v in var.netbox_backends : k => v if v.user_mgmt_username == null }
|
||||
}
|
||||
|
||||
# Dynamic path: the engine mints a user-admin token for the superuser. Requires
|
||||
# the deployer to read netbox/creds/vault-user-mgmt (policies/netbox/creds).
|
||||
data "vault_generic_secret" "user_admin" {
|
||||
for_each = local.netbox_dynamic_backends
|
||||
|
||||
path = "${each.key}/creds/vault-user-mgmt"
|
||||
}
|
||||
|
||||
# Static fallback: the single admin_token from KV, used only until a superuser is
|
||||
# named. NetBox derives the token version from the value's `nbt_` prefix, not the
|
||||
# keyword, so the same BARE token works under either scheme; reject a value that
|
||||
# carries a literal `Bearer `/`Token ` scheme prefix (a malformed header -> 403).
|
||||
data "vault_kv_secret_v2" "netbox_backend_configs" {
|
||||
for_each = local.netbox_static_backends
|
||||
|
||||
mount = "kv"
|
||||
name = "service/vault/${var.country}/${var.region}/secret_backend/${each.key}/config"
|
||||
|
||||
lifecycle {
|
||||
postcondition {
|
||||
condition = nonsensitive(
|
||||
!startswith(self.data["admin_token"], "Bearer ") &&
|
||||
!startswith(self.data["admin_token"], "Token ")
|
||||
)
|
||||
error_message = "KV admin_token for netbox backend '${each.key}' must be a BARE NetBox token with no 'Bearer '/'Token ' scheme prefix (v2: nbt_<key>.<secret>; v1: the 40-char value)."
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
# Warn (non-fatal) for any backend still on the static token: rotating the engine
|
||||
# admin seed would then break user management. Set user_mgmt_username to switch to
|
||||
# the dynamic, rotation-proof mint.
|
||||
check "netbox_user_mgmt_dynamic" {
|
||||
assert {
|
||||
condition = length(local.netbox_static_backends) == 0
|
||||
error_message = "A netbox backend has no user_mgmt_username, so user management uses the static admin_token directly and will break if that token is rotated (netbox/config/rotate). Set user_mgmt_username to a pre-existing NetBox superuser to mint the credential dynamically."
|
||||
}
|
||||
}
|
||||
|
||||
locals {
|
||||
# Per backend: the dynamically-minted user-admin token, else the static seed.
|
||||
netbox_admin_tokens = {
|
||||
for k, v in var.netbox_backends : k => (
|
||||
v.user_mgmt_username != null
|
||||
? data.vault_generic_secret.user_admin[k].data["token"]
|
||||
: data.vault_kv_secret_v2.netbox_backend_configs[k].data["admin_token"]
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
# One NetBox provider instance per backend, authenticated with its (dynamic or
|
||||
# static) admin token.
|
||||
provider "netbox" {
|
||||
alias = "by_backend"
|
||||
for_each = var.netbox_backend_aliases
|
||||
|
||||
server_url = var.netbox_backends[each.key].netbox_url
|
||||
api_token = local.netbox_admin_tokens[each.key]
|
||||
allow_insecure_https = var.netbox_backends[each.key].tls_skip_verify
|
||||
# NetBox is internal and not always reachable at plan time; the resource CRUD
|
||||
# calls surface any real incompatibility, so skip the startup version probe.
|
||||
skip_version_check = true
|
||||
}
|
||||
|
||||
# NetBox users authenticate only via Vault-minted API tokens, never the web UI,
|
||||
# so give each a random unknown password (required by the API) that no one holds.
|
||||
resource "random_password" "user" {
|
||||
for_each = var.netbox_roles
|
||||
|
||||
length = 32
|
||||
special = true
|
||||
}
|
||||
|
||||
# Declarative NetBox service users, one per engine role. The role's filename-
|
||||
# derived name is the username, so the engine role and its user match 1:1.
|
||||
resource "netbox_user" "users" {
|
||||
for_each = var.netbox_roles
|
||||
|
||||
provider = netbox.by_backend[each.value.backend]
|
||||
|
||||
username = each.value.name
|
||||
password = random_password.user[each.key].result
|
||||
active = each.value.active
|
||||
staff = each.value.staff
|
||||
email = each.value.email
|
||||
}
|
||||
|
||||
locals {
|
||||
# Flatten roles x permissions into one map keyed by "<role_path>:<index>". A
|
||||
# permission's name defaults to the role name (the username) so a single-
|
||||
# permission identity repeats nothing already encoded by the filename.
|
||||
netbox_permissions = merge([
|
||||
for role_key, role in var.netbox_roles : {
|
||||
for idx, perm in role.permissions :
|
||||
"${role_key}:${idx}" => {
|
||||
backend = role.backend
|
||||
user = role_key
|
||||
name = coalesce(perm.name, length(role.permissions) == 1 ? role.name : "${role.name}-${idx}")
|
||||
object_types = perm.object_types
|
||||
actions = perm.actions
|
||||
constraints = perm.constraints
|
||||
description = perm.description
|
||||
enabled = perm.enabled
|
||||
}
|
||||
}
|
||||
]...)
|
||||
}
|
||||
|
||||
# Object permissions granting each user its object-type/action scope.
|
||||
resource "netbox_permission" "perms" {
|
||||
for_each = local.netbox_permissions
|
||||
|
||||
provider = netbox.by_backend[each.value.backend]
|
||||
|
||||
name = each.value.name
|
||||
object_types = each.value.object_types
|
||||
actions = each.value.actions
|
||||
enabled = each.value.enabled
|
||||
description = each.value.description
|
||||
constraints = each.value.constraints
|
||||
users = [tonumber(netbox_user.users[each.value.user].id)]
|
||||
}
|
||||
@@ -0,0 +1,19 @@
|
||||
output "netbox_users" {
|
||||
description = "Map of created NetBox users (id + username; password is intentionally omitted)"
|
||||
value = {
|
||||
for k, u in netbox_user.users : k => {
|
||||
id = u.id
|
||||
username = u.username
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
output "netbox_permissions" {
|
||||
description = "Map of created NetBox object permissions"
|
||||
value = {
|
||||
for k, p in netbox_permission.perms : k => {
|
||||
id = p.id
|
||||
name = p.name
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,17 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
vault = {
|
||||
source = "hashicorp/vault"
|
||||
version = "5.6.0"
|
||||
}
|
||||
netbox = {
|
||||
source = "e-breuninger/netbox"
|
||||
version = "4.3.0"
|
||||
}
|
||||
random = {
|
||||
source = "hashicorp/random"
|
||||
version = ">= 3.5"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,46 @@
|
||||
variable "netbox_backends" {
|
||||
description = "Map of netbox secret backends (keyed by mount path); only the URL and TLS mode are needed to reach NetBox"
|
||||
type = map(object({
|
||||
netbox_url = string
|
||||
tls_skip_verify = optional(bool, false)
|
||||
# Pre-existing NetBox superuser the engine mints a dynamic user-admin token
|
||||
# for; unset means fall back to the static admin_token from KV.
|
||||
user_mgmt_username = optional(string)
|
||||
}))
|
||||
}
|
||||
|
||||
variable "netbox_roles" {
|
||||
description = "Map of netbox engine roles (the netbox_secret_backend_role config). Each role's filename-derived name is the NetBox username to create, and its permissions block is the user's object-permission set. Keyed by the role's config path."
|
||||
type = map(object({
|
||||
name = string
|
||||
backend = string
|
||||
active = optional(bool, true)
|
||||
staff = optional(bool, false)
|
||||
email = optional(string)
|
||||
permissions = optional(list(object({
|
||||
name = optional(string)
|
||||
object_types = list(string)
|
||||
actions = optional(list(string), ["view", "add", "change", "delete"])
|
||||
constraints = optional(string)
|
||||
description = optional(string)
|
||||
enabled = optional(bool, true)
|
||||
})), [])
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "netbox_backend_aliases" {
|
||||
description = "Map of netbox backend names to sanitized provider aliases"
|
||||
type = map(string)
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "country" {
|
||||
description = "Country identifier"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "region" {
|
||||
description = "Region identifier"
|
||||
type = string
|
||||
}
|
||||
@@ -0,0 +1,12 @@
|
||||
# Registers ("imports") a plugin binary in the Vault/OpenBao plugin catalog so
|
||||
# it can be mounted. The binary must already exist in the server
|
||||
# plugin_directory (installed out of band, e.g. by Puppet); `command` is its
|
||||
# filename there. The sha256 must match the on-disk binary or the server refuses
|
||||
# to launch the plugin.
|
||||
resource "vault_plugin" "this" {
|
||||
type = var.type
|
||||
name = var.name
|
||||
command = coalesce(var.command, var.name)
|
||||
sha256 = var.sha256
|
||||
version = var.plugin_version
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
vault = {
|
||||
source = "hashicorp/vault"
|
||||
version = "5.6.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,27 @@
|
||||
variable "name" {
|
||||
description = "Name to register the plugin under in the catalog (also the mount type)"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "type" {
|
||||
description = "Plugin type: secret, auth or database"
|
||||
type = string
|
||||
default = "secret"
|
||||
}
|
||||
|
||||
variable "command" {
|
||||
description = "Plugin binary filename relative to the server plugin_directory. Defaults to the plugin name."
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "sha256" {
|
||||
description = "SHA-256 of the installed plugin binary; must match the on-disk binary"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "plugin_version" {
|
||||
description = "Optional plugin version to register the catalog entry under"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
# Mounts the rancher secrets engine and writes its connection config via the
|
||||
# ranchervaultsecret provider. The plugin is registered ("imported") in the
|
||||
# catalog separately (config/plugins/vault-plugin-secrets-rancher.yaml). Seeded
|
||||
# service-account tokens and roles are managed by the sibling modules.
|
||||
resource "rancher_secret_backend" "this" {
|
||||
path = var.path
|
||||
plugin = var.plugin
|
||||
description = var.description
|
||||
rancher_url = var.rancher_url
|
||||
ca_cert = var.ca_cert
|
||||
tls_skip_verify = var.tls_skip_verify
|
||||
request_timeout_seconds = var.request_timeout_seconds
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
rancher = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/ranchervaultsecret"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
variable "path" {
|
||||
description = "Mount path of the rancher secrets engine (e.g. \"rancher\")"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "plugin" {
|
||||
description = "Registered plugin name to mount (the catalog name = mount type)"
|
||||
type = string
|
||||
default = "vault-plugin-secrets-rancher"
|
||||
}
|
||||
|
||||
variable "description" {
|
||||
description = "Human-friendly description of the mount"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "rancher_url" {
|
||||
description = "Base URL of the Rancher server (e.g. https://rancher.k8s.syd1.au.unkin.net)"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "ca_cert" {
|
||||
description = "PEM CA certificate that signed the Rancher server's TLS cert (optional; omit to use the system trust store)"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "tls_skip_verify" {
|
||||
description = "Skip TLS verification of the Rancher server (not recommended)"
|
||||
type = bool
|
||||
default = false
|
||||
}
|
||||
|
||||
variable "request_timeout_seconds" {
|
||||
description = "HTTP timeout in seconds for calls from the plugin to Rancher"
|
||||
type = number
|
||||
default = 30
|
||||
}
|
||||
@@ -0,0 +1,11 @@
|
||||
# A role that mints short-lived, optionally cluster-scoped rancher tokens from a
|
||||
# service account. Reading rancher/creds/<name> produces a lease-bound token.
|
||||
resource "rancher_secret_backend_role" "this" {
|
||||
backend = var.backend
|
||||
name = var.name
|
||||
service_account = var.service_account
|
||||
cluster_name = var.cluster_name
|
||||
description = var.description
|
||||
ttl = var.ttl
|
||||
max_ttl = var.max_ttl
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
rancher = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/ranchervaultsecret"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
variable "backend" {
|
||||
description = "Mount path of the rancher secrets engine this role lives on"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "name" {
|
||||
description = "Role name"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "service_account" {
|
||||
description = "Service account (seeded token) used to mint credentials; its user's RBAC is inherited by minted tokens"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "cluster_name" {
|
||||
description = "Downstream cluster to scope minted tokens to (empty = full Rancher-server scope)"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "description" {
|
||||
description = "Description applied to each minted Rancher token"
|
||||
type = string
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "ttl" {
|
||||
description = "Default lease TTL in seconds for tokens minted from this role"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "max_ttl" {
|
||||
description = "Maximum lease TTL in seconds for tokens minted from this role"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
@@ -0,0 +1,18 @@
|
||||
# Seeds an auto-rotated rancher service-account token. The seed token is
|
||||
# sensitive and read from KV, not stored in git:
|
||||
# kv/service/vault/<country>/<region>/secret_backend/<backend>/service_account/<name>
|
||||
# Expected keys: token (required), token_name (optional, the ext.cattle.io Token
|
||||
# metadata.name so the engine can delete the seed after the first rotation).
|
||||
data "vault_kv_secret_v2" "seed" {
|
||||
mount = "kv"
|
||||
name = "service/vault/${var.country}/${var.region}/secret_backend/${var.backend}/service_account/${var.name}"
|
||||
}
|
||||
|
||||
resource "rancher_secret_backend_service_account" "this" {
|
||||
backend = var.backend
|
||||
name = var.name
|
||||
token = data.vault_kv_secret_v2.seed.data["token"]
|
||||
token_name = lookup(data.vault_kv_secret_v2.seed.data, "token_name", null)
|
||||
token_ttl = var.token_ttl
|
||||
rotation_period = var.rotation_period
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10"
|
||||
required_providers {
|
||||
vault = {
|
||||
source = "hashicorp/vault"
|
||||
version = "5.6.0"
|
||||
}
|
||||
rancher = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/ranchervaultsecret"
|
||||
version = "0.1.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
variable "backend" {
|
||||
description = "Mount path of the rancher secrets engine this service account lives on"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "name" {
|
||||
description = "Service-account name"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "country" {
|
||||
description = "Country code, used to locate the seed token in KV"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "region" {
|
||||
description = "Region code, used to locate the seed token in KV"
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "token_ttl" {
|
||||
description = "Lifetime in seconds requested for each rotated replacement token (default: engine default, 90d)"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
|
||||
variable "rotation_period" {
|
||||
description = "Seconds a token is used before rotation (default: engine default, 45d). Must be < token_ttl"
|
||||
type = number
|
||||
default = null
|
||||
}
|
||||
@@ -285,10 +285,189 @@ variable "kubernetes_secret_backend_role" {
|
||||
allowed_kubernetes_namespaces = optional(list(string), ["*"])
|
||||
kubernetes_role_type = optional(string, "Role")
|
||||
extra_labels = optional(map(string), {})
|
||||
service_account_name = optional(string)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "litellm_secret_backend" {
|
||||
description = "Map of LiteLLM secret engines to create (mount + config). The master key is read from KV"
|
||||
type = map(object({
|
||||
plugin = optional(string, "vault-plugin-secrets-litellm")
|
||||
description = optional(string)
|
||||
base_url = string
|
||||
request_timeout_seconds = optional(number, 30)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "litellm_secret_backend_role" {
|
||||
description = "Map of LiteLLM roles to create"
|
||||
type = map(object({
|
||||
name = string
|
||||
backend = string
|
||||
models = optional(list(string))
|
||||
max_budget = optional(number)
|
||||
key_alias_prefix = optional(string)
|
||||
ttl = optional(number)
|
||||
max_ttl = optional(number)
|
||||
metadata = optional(map(string))
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "plugins" {
|
||||
description = "Map of plugins to import (register) in the catalog, keyed by catalog name"
|
||||
type = map(object({
|
||||
name = string
|
||||
type = optional(string, "secret")
|
||||
command = optional(string)
|
||||
sha256 = string
|
||||
version = optional(string)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "gpg_secret_backend" {
|
||||
description = "Map of GPG/OpenPGP secret engines to mount (path => registered plugin + description). The plugin is registered separately via config/plugins."
|
||||
type = map(object({
|
||||
plugin = optional(string, "vault-plugin-secrets-gpg")
|
||||
description = optional(string)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "gpg_key" {
|
||||
description = "Map of OpenPGP keys to manage in a gpg engine mount"
|
||||
type = map(object({
|
||||
name = string
|
||||
backend = string
|
||||
algorithm = optional(string, "rsa-3072")
|
||||
identity = optional(string)
|
||||
exportable = optional(bool, false)
|
||||
deletion_allowed = optional(bool, false)
|
||||
min_decryption_version = optional(number)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "rancher_secret_backend" {
|
||||
description = "Map of rancher token secret engines to create (mount + config)"
|
||||
type = map(object({
|
||||
plugin = optional(string, "vault-plugin-secrets-rancher")
|
||||
description = optional(string)
|
||||
rancher_url = string
|
||||
ca_cert = optional(string)
|
||||
tls_skip_verify = optional(bool, false)
|
||||
request_timeout_seconds = optional(number, 30)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "rancher_secret_backend_service_account" {
|
||||
description = "Map of seeded, auto-rotated rancher service-account tokens (seed token read from KV)"
|
||||
type = map(object({
|
||||
name = string
|
||||
backend = string
|
||||
token_ttl = optional(number)
|
||||
rotation_period = optional(number)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "rancher_secret_backend_role" {
|
||||
description = "Map of rancher token-minting roles to create"
|
||||
type = map(object({
|
||||
name = string
|
||||
backend = string
|
||||
service_account = string
|
||||
cluster_name = optional(string)
|
||||
description = optional(string)
|
||||
ttl = optional(number)
|
||||
max_ttl = optional(number)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "gitea_secret_backend" {
|
||||
description = "Map of gitea token secret engines to create (mount + config; seeded admin creds read from KV)"
|
||||
type = map(object({
|
||||
plugin = optional(string, "vault-plugin-secrets-gitea")
|
||||
description = optional(string)
|
||||
gitea_url = string
|
||||
ca_cert = optional(string)
|
||||
tls_skip_verify = optional(bool, false)
|
||||
request_timeout_seconds = optional(number, 30)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "gitea_secret_backend_role" {
|
||||
description = "Map of gitea token-minting roles to create"
|
||||
type = map(object({
|
||||
name = string
|
||||
backend = string
|
||||
username = string
|
||||
scopes = list(string)
|
||||
token_name_prefix = optional(string)
|
||||
ttl = optional(number)
|
||||
max_ttl = optional(number)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "netbox_secret_backend" {
|
||||
description = "Map of netbox token secret engines to create (mount + config; seeded admin token read from KV)"
|
||||
type = map(object({
|
||||
plugin = optional(string, "vault-plugin-secrets-netbox")
|
||||
description = optional(string)
|
||||
netbox_url = string
|
||||
token_version = optional(number, 2)
|
||||
ca_cert = optional(string)
|
||||
tls_skip_verify = optional(bool, false)
|
||||
request_timeout_seconds = optional(number, 30)
|
||||
# Pre-existing NetBox superuser (or add_user + add_token + grant_token) the
|
||||
# engine mints an ephemeral user-admin token for, so netbox_user_management
|
||||
# authenticates with a Vault-minted credential derived from the single static
|
||||
# admin token instead of a second static one. Unset = use the static
|
||||
# admin_token directly (bootstrap/degraded; breaks after admin-token rotation).
|
||||
user_mgmt_username = optional(string)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "netbox_secret_backend_role" {
|
||||
description = "Map of netbox engine roles; each role's filename-derived name is both the engine role and the NetBox username it mints tokens for, and its permissions block is the user's object-permission set"
|
||||
type = map(object({
|
||||
name = string
|
||||
backend = string
|
||||
netbox_username = optional(string)
|
||||
netbox_user_id = optional(number)
|
||||
write_enabled = optional(bool, false)
|
||||
description = optional(string)
|
||||
ttl = optional(number)
|
||||
max_ttl = optional(number)
|
||||
active = optional(bool, true)
|
||||
staff = optional(bool, false)
|
||||
email = optional(string)
|
||||
permissions = optional(list(object({
|
||||
name = optional(string)
|
||||
object_types = list(string)
|
||||
actions = optional(list(string), ["view", "add", "change", "delete"])
|
||||
constraints = optional(string)
|
||||
description = optional(string)
|
||||
enabled = optional(bool, true)
|
||||
})), [])
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "netbox_backend_aliases" {
|
||||
description = "Map of netbox backend names to sanitized provider aliases"
|
||||
type = map(string)
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "policy_auth_map" {
|
||||
description = "Map of auth mounts -> auth roles -> policy names"
|
||||
type = map(map(list(string)))
|
||||
|
||||
@@ -0,0 +1,14 @@
|
||||
# Allow the terragrunt-enc runner to generate credentials for the
|
||||
# terraform-enc role in consul (used to lock/write its terragrunt state under
|
||||
# infra/terraform/enc/ on the consul backend).
|
||||
---
|
||||
rules:
|
||||
- path: "consul_root/au/syd1/creds/terraform-enc"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- terraform_enc
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_enc
|
||||
@@ -0,0 +1,11 @@
|
||||
---
|
||||
rules:
|
||||
- path: "consul_root/au/syd1/creds/terraform-infra"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- terraform_infra
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_infra
|
||||
@@ -0,0 +1,11 @@
|
||||
---
|
||||
rules:
|
||||
- path: "consul_root/au/syd1/creds/terraform-rancher"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- terraform_rancher
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_rancher
|
||||
@@ -0,0 +1,42 @@
|
||||
# Allow the vault deployer to manage the gitea token secrets engine: its
|
||||
# connection config (seeded admin credentials), in-place root rotation, and
|
||||
# token-minting roles.
|
||||
#
|
||||
# Scoped to gitea/* only, and deliberately excludes gitea/creds/* — minting
|
||||
# tokens is for consumers, not the deployer. The plugin-catalog grant needed to
|
||||
# import the plugin is the shared, sudo-protected wildcard in
|
||||
# policies/sys/plugins/catalog/admin.yaml (already covers this plugin), and
|
||||
# mounting the engine uses the deployer's existing sys/mounts/* access, so no
|
||||
# new catalog/mount grant is added here (mirrors the rancher engine).
|
||||
---
|
||||
rules:
|
||||
# Engine connection config (Gitea URL, TLS, seeded admin username/password).
|
||||
- path: "gitea/config"
|
||||
capabilities:
|
||||
- create
|
||||
- read
|
||||
- update
|
||||
- delete
|
||||
# In-place rotation of the seeded admin password (write-only trigger).
|
||||
- path: "gitea/config/rotate-root"
|
||||
capabilities:
|
||||
- create
|
||||
- update
|
||||
# Token-minting roles.
|
||||
- path: "gitea/roles/*"
|
||||
capabilities:
|
||||
- create
|
||||
- read
|
||||
- update
|
||||
- delete
|
||||
- list
|
||||
- path: "gitea/roles"
|
||||
capabilities:
|
||||
- read
|
||||
- list
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- tf_vault
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_vault
|
||||
@@ -0,0 +1,14 @@
|
||||
# Lets the agents AppRole mint ephemeral Gitea tokens for the unkin-agent bot,
|
||||
# so AI coding agents authenticate to git.unkin.net as their own least-privilege
|
||||
# identity instead of Ben's account. Reading gitea/creds/unkin-agent returns a
|
||||
# lease-bound token scoped by the role (write:repository, write:issue, read:user
|
||||
# -- never merge/admin). Mirrors the agent-* Kubernetes creds binding pattern.
|
||||
---
|
||||
rules:
|
||||
- path: "gitea/creds/unkin-agent"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- agents
|
||||
@@ -0,0 +1,35 @@
|
||||
# Allow the vault deployer to import the gpg plugin and manage its OpenPGP keys.
|
||||
#
|
||||
# terraform-vault registers the plugin itself (vault_plugin -> sys/plugins/catalog,
|
||||
# a sudo-protected path) and manages keys via the gpgvaultsecret provider, so the
|
||||
# deployer needs catalog access on top of the mount access it already has
|
||||
# (sys/mounts/*). Without this, apply 403s on the plugin registration and on
|
||||
# gpg/keys writes.
|
||||
---
|
||||
rules:
|
||||
# Import / register (and deregister) the gpg plugin in the catalog.
|
||||
- path: "sys/plugins/catalog/secret/vault-plugin-secrets-gpg"
|
||||
capabilities:
|
||||
- create
|
||||
- read
|
||||
- update
|
||||
- delete
|
||||
- sudo
|
||||
# Manage keys (create/rotate/config/delete) in the gpg mount.
|
||||
- path: "gpg/keys/*"
|
||||
capabilities:
|
||||
- create
|
||||
- read
|
||||
- update
|
||||
- delete
|
||||
- list
|
||||
- path: "gpg/keys"
|
||||
capabilities:
|
||||
- read
|
||||
- list
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- tf_vault
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_vault
|
||||
@@ -0,0 +1,12 @@
|
||||
# Allow the logarchiver service (logging namespace, SA logarchiver) to read the
|
||||
# logarchive public key. A plain read on gpg/keys/logarchive returns the armored
|
||||
# public_key; no decrypt/export capability is granted (decrypt stays operator-only).
|
||||
---
|
||||
rules:
|
||||
- path: "gpg/keys/logarchive"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
k8s/au/syd1:
|
||||
- logging_logarchiver
|
||||
@@ -0,0 +1,12 @@
|
||||
# Allow access to agent-certs Kubernetes credentials
|
||||
---
|
||||
rules:
|
||||
- path: "kubernetes/au/syd1/creds/agent-certs"
|
||||
capabilities:
|
||||
- update
|
||||
|
||||
auth:
|
||||
ldap:
|
||||
- kubernetes_au_syd1_cluster_operator
|
||||
approle:
|
||||
- agents
|
||||
@@ -0,0 +1,12 @@
|
||||
# Allow access to agent-dhcp Kubernetes credentials
|
||||
---
|
||||
rules:
|
||||
- path: "kubernetes/au/syd1/creds/agent-dhcp"
|
||||
capabilities:
|
||||
- update
|
||||
|
||||
auth:
|
||||
ldap:
|
||||
- kubernetes_au_syd1_cluster_operator
|
||||
approle:
|
||||
- agents
|
||||
@@ -0,0 +1,12 @@
|
||||
# Allow access to agent-dns Kubernetes credentials
|
||||
---
|
||||
rules:
|
||||
- path: "kubernetes/au/syd1/creds/agent-dns"
|
||||
capabilities:
|
||||
- update
|
||||
|
||||
auth:
|
||||
ldap:
|
||||
- kubernetes_au_syd1_cluster_operator
|
||||
approle:
|
||||
- agents
|
||||
@@ -0,0 +1,12 @@
|
||||
# Allow access to agent-storage Kubernetes credentials
|
||||
---
|
||||
rules:
|
||||
- path: "kubernetes/au/syd1/creds/agent-storage"
|
||||
capabilities:
|
||||
- update
|
||||
|
||||
auth:
|
||||
ldap:
|
||||
- kubernetes_au_syd1_cluster_operator
|
||||
approle:
|
||||
- agents
|
||||
@@ -0,0 +1,17 @@
|
||||
# Allow the agents AppRole to manage the kubernetes KV subtree (no delete)
|
||||
---
|
||||
rules:
|
||||
- path: "kv/data/kubernetes/*"
|
||||
capabilities:
|
||||
- create
|
||||
- read
|
||||
- update
|
||||
- list
|
||||
- path: "kv/metadata/kubernetes/*"
|
||||
capabilities:
|
||||
- read
|
||||
- list
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- agents
|
||||
@@ -0,0 +1,17 @@
|
||||
# Allow ghp to read its GitHub App credentials and encryption key
|
||||
#
|
||||
# kv/kubernetes/ghp/github-app (app_id/client_id/client_secret/private_key)
|
||||
# kv/kubernetes/ghp/app (encryption_key)
|
||||
---
|
||||
rules:
|
||||
- path: "kv/data/kubernetes/ghp/*"
|
||||
capabilities:
|
||||
- read
|
||||
- path: "kv/metadata/kubernetes/ghp/*"
|
||||
capabilities:
|
||||
- read
|
||||
- list
|
||||
|
||||
auth:
|
||||
k8s/au/syd1:
|
||||
- ghp
|
||||
@@ -0,0 +1,14 @@
|
||||
# Allow the terragrunt-enc runner to read the encapi environment secret
|
||||
# (ENCAPI_WRITE_TOKEN), so `make apply` can write ENC data (statuses, roles,
|
||||
# nodes) to encapi via the encapi Terraform provider.
|
||||
---
|
||||
rules:
|
||||
- path: "kv/data/kubernetes/namespace/encapi/default/environment"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- terraform_enc
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_enc
|
||||
@@ -0,0 +1,18 @@
|
||||
# Allow the terraform-infra runner to read the NetBox + KeaAPI tokens
|
||||
# (netbox_token / kea_token fields) used by the netbox and kea providers.
|
||||
---
|
||||
rules:
|
||||
- path: "kv/data/service/terraform/infra"
|
||||
capabilities:
|
||||
- read
|
||||
# vault_kv_secret_v2 (terraform-infra providers.tf data source) reads the kv-v2
|
||||
# metadata path on every plan/apply; a 403 here fails the plan.
|
||||
- path: "kv/metadata/service/terraform/infra"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- terraform_infra
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_infra
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user