Why: after the engine is first configured, rotate-root changes the live admin
password so it diverges from the KV seed. Re-reading the (possibly stale) seed
on a later apply must not push it back and clobber the rotated password. Ben
asked that the seed be used only when initially creating the config.
Change:
- Add lifecycle ignore_changes on admin_username/admin_password to the
gitea_secret_backend resource, making the module create-only for the seeded
credential. Noted inline that the rancher/litellm seed modules lack this.
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
Why: teabot's implementer and reviewer bot users should mint ephemeral,
scoped Gitea tokens on demand instead of holding standing personal access
tokens (Gitea tokens never expire on their own). This registers and mounts
the new vault-plugin-secrets-gitea engine and declares its roles, mirroring
the rancher engine wiring.
Change:
- Register the plugin in the catalog (config/plugins/vault-plugin-secrets-gitea.yaml)
pinned to the released v0.1.0 binary sha256.
- Add gitea_secret_backend + gitea_secret_backend_role modules and wire them
through config.hcl, terragrunt.hcl, and vault_cluster variables/main, using
the giteavaultsecret provider (terraform-unkin registry, v0.1.0).
- Mount the engine at gitea/ against https://git.unkin.net; seeded site-admin
credentials are read from KV (service/vault/au/syd1/secret_backend/gitea/config).
- Add teabot-implementer (write:repository, write:issue) and teabot-reviewer
(read:repository, write:issue) roles, ttl 1h / max_ttl 4h.
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv