From f0a61dc35211c7bca5c5ce6de034ddeb5daac6cf Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Wed, 19 Aug 2026 21:37:57 +1000 Subject: [PATCH 1/2] Register vault-plugin-secrets-arrstack in the plugin catalog Import the arrstack secrets plugin (v0.1.0) into the OpenBao plugin catalog so later PRs can mount the engine. Registration is the first of three stacked, independently-applied steps (register -> policy -> resources) per the never-bundle rule. The plugins map glob and module.plugin already exist, so this only adds the catalog entry; the sha256 pins the released v0.1.0 binary. Apply order: run this only AFTER the Puppet plugin-install PR (#521, merged) has placed the binary at /opt/openbao-plugins/vault-plugin-secrets-arrstack on the OpenBao nodes. Registration fails until the binary is present. --- config/plugins/vault-plugin-secrets-arrstack.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+) create mode 100644 config/plugins/vault-plugin-secrets-arrstack.yaml diff --git a/config/plugins/vault-plugin-secrets-arrstack.yaml b/config/plugins/vault-plugin-secrets-arrstack.yaml new file mode 100644 index 0000000..fc92851 --- /dev/null +++ b/config/plugins/vault-plugin-secrets-arrstack.yaml @@ -0,0 +1,13 @@ +# config/plugins/vault-plugin-secrets-arrstack.yaml +# Imports (registers) the arrstack secrets plugin in the catalog. Filename = +# catalog name = mount type. The binary is installed on the OpenBao nodes by +# Puppet (openbao-plugin-secrets-arrstack RPM -> +# /opt/openbao-plugins/vault-plugin-secrets-arrstack). +# +# sha256 pins the released v0.1.0 binary; bump it in lockstep with any RPM +# upgrade or OpenBao will refuse to launch the plugin. Registration only +# succeeds once the Puppet PR has installed the binary on the nodes. +type: secret +command: vault-plugin-secrets-arrstack +version: "0.1.0" +sha256: "f8ee60ca7ba14819976acb7dc4cfb6799e3e8da8f871d0bb2bd18d1d9e537972" -- 2.47.3 From 5862ae974c159be08175f00539ffb5312dbebe53 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Wed, 19 Aug 2026 21:38:28 +1000 Subject: [PATCH 2/2] Add arrstack Vault policies (deployer, KV read, consumer creds) Grant the Vault access the arrstack engine needs, before any engine resources exist. Second of three stacked steps (register -> policy -> resources). Adds: - policies/arrstack/admin.yaml: the terraform-vault deployer may create/read/update/delete arrstack/config and manage arrstack/roles/*. - policies/kv/.../arrproxy-admin-token/read.yaml: the deployer may read the KV-seeded arrproxy admin token (data + metadata paths) that the engine config sources; the existing secret_backends_read policy does not cover this kubernetes/namespace KV path. - policies/arrstack/creds/{sonarr,radarr,prowlarr}.yaml: each terraform- run may read its own arrstack/creds/ to mint a scoped key. Policy YAMLs are auto-discovered by policies/policies.hcl, so no wiring changes are needed. Apply order: after PR-1 (register). Safe to apply before the engine exists since these only grant capabilities on paths. --- policies/arrstack/admin.yaml | 27 +++++++++++++++++++ policies/arrstack/creds/prowlarr.yaml | 12 +++++++++ policies/arrstack/creds/radarr.yaml | 12 +++++++++ policies/arrstack/creds/sonarr.yaml | 12 +++++++++ .../default/arrproxy-admin-token/read.yaml | 22 +++++++++++++++ 5 files changed, 85 insertions(+) create mode 100644 policies/arrstack/admin.yaml create mode 100644 policies/arrstack/creds/prowlarr.yaml create mode 100644 policies/arrstack/creds/radarr.yaml create mode 100644 policies/arrstack/creds/sonarr.yaml create mode 100644 policies/kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token/read.yaml diff --git a/policies/arrstack/admin.yaml b/policies/arrstack/admin.yaml new file mode 100644 index 0000000..96b86d8 --- /dev/null +++ b/policies/arrstack/admin.yaml @@ -0,0 +1,27 @@ +# Allow management of the arrstack secrets engine (config and roles) by the +# terraform-vault deployer. +--- +rules: + - path: "arrstack/config" + capabilities: + - create + - update + - read + - delete + - path: "arrstack/roles/*" + capabilities: + - create + - update + - delete + - read + - list + - path: "arrstack/roles" + capabilities: + - read + - list + +auth: + approle: + - tf_vault + k8s/au/syd1: + - woodpecker_terraform_vault diff --git a/policies/arrstack/creds/prowlarr.yaml b/policies/arrstack/creds/prowlarr.yaml new file mode 100644 index 0000000..5922685 --- /dev/null +++ b/policies/arrstack/creds/prowlarr.yaml @@ -0,0 +1,12 @@ +# Allow the terraform-prowlarr run to mint a Prowlarr-scoped arrproxy key. +--- +rules: + - path: "arrstack/creds/prowlarr" + capabilities: + - read + +auth: + approle: + - terraform_prowlarr + k8s/au/syd1: + - woodpecker_terraform_prowlarr diff --git a/policies/arrstack/creds/radarr.yaml b/policies/arrstack/creds/radarr.yaml new file mode 100644 index 0000000..7b79acf --- /dev/null +++ b/policies/arrstack/creds/radarr.yaml @@ -0,0 +1,12 @@ +# Allow the terraform-radarr run to mint a Radarr-scoped arrproxy key. +--- +rules: + - path: "arrstack/creds/radarr" + capabilities: + - read + +auth: + approle: + - terraform_radarr + k8s/au/syd1: + - woodpecker_terraform_radarr diff --git a/policies/arrstack/creds/sonarr.yaml b/policies/arrstack/creds/sonarr.yaml new file mode 100644 index 0000000..5e5ae54 --- /dev/null +++ b/policies/arrstack/creds/sonarr.yaml @@ -0,0 +1,12 @@ +# Allow the terraform-sonarr run to mint a Sonarr-scoped arrproxy key. +--- +rules: + - path: "arrstack/creds/sonarr" + capabilities: + - read + +auth: + approle: + - terraform_sonarr + k8s/au/syd1: + - woodpecker_terraform_sonarr diff --git a/policies/kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token/read.yaml b/policies/kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token/read.yaml new file mode 100644 index 0000000..66d1547 --- /dev/null +++ b/policies/kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token/read.yaml @@ -0,0 +1,22 @@ +# Allow the terraform-vault deployer to read the seeded arrproxy admin token so +# the arrstack engine config module can source it. The token is seeded by +# argocd-apps #384 at kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token. +# The deployer's existing secret_backends_read policy only covers +# kv/data/service/vault/+/+/secret_backend/*, which does not match this +# kubernetes/namespace path, so this adds the minimal read grant rather than +# duplicating the secret into the litellm-style path. vault_kv_secret_v2 also +# reads the kv-v2 metadata path on every plan/apply, so grant that too. +--- +rules: + - path: "kv/data/kubernetes/namespace/arrstack/default/arrproxy-admin-token" + capabilities: + - read + - path: "kv/metadata/kubernetes/namespace/arrstack/default/arrproxy-admin-token" + capabilities: + - read + +auth: + approle: + - tf_vault + k8s/au/syd1: + - woodpecker_terraform_vault -- 2.47.3