Restore ghp secret backend + roles (config now seeded) #130

Merged
benvin merged 1 commits from benvin/add-ghp-backend-back into master 2026-08-19 23:47:32 +10:00
Member

Why

Reverts the temporary removal in #129. That PR deleted the ghp backend + role
config YAMLs to unblock the master apply, which was failing with:

Error: no secret found at "kv/data/service/vault/au/syd1/secret_backend/ghp/config"
  from module.ghp_secret_backend["ghp"].data.vault_kv_secret_v2.config

The ghp config KV is now seeded: kv/data/service/vault/au/syd1/secret_backend/ghp/config
holds key admin_token, and the ghp service secret
kv/kubernetes/namespace/ghp/default/app carries the matching service_token.
With the KV populated, data.vault_kv_secret_v2.config resolves, so the ghp
secret backend + role can be created. The ghp module wiring, plugin
registration, and policies were never removed (they stayed on master), so
restoring these two YAMLs re-populates the for_each maps and instantiates the
backend + role against the seeded config.

Changes

  • Restore config/ghp_secret_backend/ghp.yaml.
  • Restore config/ghp_secret_backend_role/ghp/agent.yaml.

Net diff vs master is exactly the re-addition of those two files
(byte-identical to their pre-#129 content, the mirror-inverse of #129).

Sequence

Final step (4/4) of the remove -> grant write policy -> seed KV -> add-back
sequence: #129 (remove) -> #128 (grant) -> KV seed -> this PR (add back).

Verification

  • tofu fmt clean, yamllint passes (pre-commit hooks green), terragrunt validate succeeds (only unrelated vault_kv_secret_v2 deprecation warnings).
  • tofu init installs the vault-secrets-ghp provider with no plugin/catalog error.
  • ghp config KV path confirmed seeded with admin_token, so the previously-failing data source now resolves.
  • A full privileged plan is not runnable under the agent AppRole (it lacks the policy to mint the consul backend token), so the created/destroyed resource counts are not machine-confirmed here; the git diff is exactly the two file additions, so no config-driven destroys are introduced.
  • Note: the ghp backend mount at apply requires the vault-plugin-secrets-ghp binary present on the OpenBao nodes (pre-existing Puppet-managed plugin).
## Why Reverts the temporary removal in #129. That PR deleted the ghp backend + role config YAMLs to unblock the `master` apply, which was failing with: ``` Error: no secret found at "kv/data/service/vault/au/syd1/secret_backend/ghp/config" from module.ghp_secret_backend["ghp"].data.vault_kv_secret_v2.config ``` The ghp config KV is now seeded: `kv/data/service/vault/au/syd1/secret_backend/ghp/config` holds key `admin_token`, and the ghp service secret `kv/kubernetes/namespace/ghp/default/app` carries the matching `service_token`. With the KV populated, `data.vault_kv_secret_v2.config` resolves, so the ghp secret backend + role can be created. The ghp module wiring, plugin registration, and policies were never removed (they stayed on `master`), so restoring these two YAMLs re-populates the `for_each` maps and instantiates the backend + role against the seeded config. ## Changes - Restore `config/ghp_secret_backend/ghp.yaml`. - Restore `config/ghp_secret_backend_role/ghp/agent.yaml`. Net diff vs `master` is exactly the re-addition of those two files (byte-identical to their pre-#129 content, the mirror-inverse of #129). ## Sequence Final step (4/4) of the remove -> grant write policy -> seed KV -> add-back sequence: #129 (remove) -> #128 (grant) -> KV seed -> this PR (add back). ## Verification - `tofu fmt` clean, `yamllint` passes (pre-commit hooks green), `terragrunt validate` succeeds (only unrelated `vault_kv_secret_v2` deprecation warnings). - `tofu init` installs the `vault-secrets-ghp` provider with no plugin/catalog error. - ghp config KV path confirmed seeded with `admin_token`, so the previously-failing data source now resolves. - A full privileged `plan` is not runnable under the agent AppRole (it lacks the policy to mint the consul backend token), so the created/destroyed resource counts are not machine-confirmed here; the git diff is exactly the two file additions, so no config-driven destroys are introduced. - Note: the ghp backend mount at apply requires the `vault-plugin-secrets-ghp` binary present on the OpenBao nodes (pre-existing Puppet-managed plugin).
unkin-agent added 1 commit 2026-08-19 23:34:40 +10:00
Restore ghp secret backend + roles (config now seeded)
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
31d7a6a427
Reverts the temporary removal in #129. The ghp config KV path
kv/data/service/vault/au/syd1/secret_backend/ghp/config (key admin_token)
is now seeded, and the ghp service secret carries the matching service_token,
so data.vault_kv_secret_v2.config resolves and the backend + role can be
created.

Restore config/ghp_secret_backend/ghp.yaml.
Restore config/ghp_secret_backend_role/ghp/agent.yaml.

Net diff vs master is exactly the re-addition of those two files (mirror-inverse
of #129). Final step of the remove -> grant -> seed -> add-back sequence.
benvin merged commit 392c5d2ac7 into master 2026-08-19 23:47:32 +10:00
benvin deleted branch benvin/add-ghp-backend-back 2026-08-19 23:47:32 +10:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/terraform-vault#130