Manage the litellm plugin via config/plugins (import existing registration) #90

Merged
benvin merged 1 commits from benvin/import-litellm-plugin into master 2026-07-18 14:55:34 +10:00
Owner

Bring the litellm plugin under terraform management like the gpg one, using the new plugin-import module (#89).

Why

The litellm plugin was registered manually before terraform owned the catalog. If we just add it to config/plugins/, the first apply tries to create a catalog entry that already exists and fails. So its state must be imported first.

Changes

  • Add config/plugins/vault-plugin-secrets-litellm.yaml (sha256 = released v0.1.1 openbao binary from the RPM Puppet installs).

Manual pre-step (before apply)

Import the existing registration into state, and verify the sha matches the live catalog:

cd environments/au/syd1
# confirm the live sha first:
bao read sys/plugins/catalog/secret/vault-plugin-secrets-litellm
# import into state:
terragrunt import \
  'module.plugin["vault-plugin-secrets-litellm"].vault_plugin.this' \
  secret/vault-plugin-secrets-litellm

If the live sha differs from the yaml, update the yaml to match (or expect a benign re-register to the on-disk v0.1.1 sha). Needs the deployer's plugin-catalog access (#88, already merged).

Bring the litellm plugin under terraform management like the gpg one, using the new plugin-import module (#89). ## Why The litellm plugin was registered **manually** before terraform owned the catalog. If we just add it to `config/plugins/`, the first apply tries to *create* a catalog entry that already exists and fails. So its state must be imported first. ## Changes - Add `config/plugins/vault-plugin-secrets-litellm.yaml` (`sha256` = released **v0.1.1** openbao binary from the RPM Puppet installs). ## Manual pre-step (before apply) Import the existing registration into state, and verify the sha matches the live catalog: ```sh cd environments/au/syd1 # confirm the live sha first: bao read sys/plugins/catalog/secret/vault-plugin-secrets-litellm # import into state: terragrunt import \ 'module.plugin["vault-plugin-secrets-litellm"].vault_plugin.this' \ secret/vault-plugin-secrets-litellm ``` If the live sha differs from the yaml, update the yaml to match (or expect a benign re-register to the on-disk v0.1.1 sha). Needs the deployer's plugin-catalog access (#88, already merged).
unkinben added 1 commit 2026-07-17 23:16:49 +10:00
Manage the litellm plugin via config/plugins (import existing registration)
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/plan Pipeline was successful
f7c738fbc2
Bring the litellm plugin under terraform management like the gpg one. It was
registered manually before terraform owned the catalog, so its state must be
imported before applying, otherwise apply fails creating an entry that already
exists.

- Add config/plugins/vault-plugin-secrets-litellm.yaml (sha256 = released v0.1.1
  openbao binary; verify against the live catalog on import).

Manual pre-step before apply:
  cd environments/au/syd1
  terragrunt import \
    'module.plugin["vault-plugin-secrets-litellm"].vault_plugin.this' \
    secret/vault-plugin-secrets-litellm
Owner

Create another pr to give the deployed access to the path used to import all plugins.

Create another pr to give the deployed access to the path used to import all plugins.
benvin merged commit 193c17d1bc into master 2026-07-18 14:55:34 +10:00
benvin deleted branch benvin/import-litellm-plugin 2026-07-18 14:55:34 +10:00
Sign in to join this conversation.
No Reviewers
No Label
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/terraform-vault#90