1f03bcdc67
ci/woodpecker/push/apply Pipeline was successful
## Why Engine plugin v0.2.0 (catalog bumped in #144) added a `methods` field to arrstack roles, pinning a minted arrproxy key to a set of HTTP methods so a read-only integration can hold a key that cannot write. Provider v0.2.0 (just published to the `terraform-unkin` registry) exposes it as an optional set attribute, but the module had no input for it, so no role yaml could use it. ## How - Bumps the `vault-secrets-arrstack` provider pin from 0.1.1 to 0.2.0 in `environments/root.hcl` and both arrstack modules. - Adds an optional `methods` input to `modules/vault_cluster/modules/arrstack_secret_backend_role` and passes it through to the resource. - Threads `methods` through the `vault_cluster` `arrstack_secret_backend_role` object type, so a role yaml may now carry a `methods:` list and it flows via the existing config.hcl merge with no discovery change. `methods` defaults to `null` rather than `[]`: the provider reads an unrestricted role back as null, so a null default keeps a role yaml that omits the field drift-free. An empty-set default would plan `null -> []` on every existing role. **Expected plan: no resource changes.** No role yaml changes here, so the plan should be a provider-version-only diff (provider upgrade, zero add/change/destroy). Follow-up PR scopes the mediamark role to GET/HEAD. Reviewed-on: #145 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
76 lines
2.0 KiB
HCL
76 lines
2.0 KiB
HCL
# Generate root backend.tf
|
|
generate "backend" {
|
|
path = "backend.tf"
|
|
if_exists = "overwrite"
|
|
contents = <<EOF
|
|
locals {
|
|
vault_addr = "https://vault.service.consul:8200"
|
|
}
|
|
|
|
provider "vault" {
|
|
address = local.vault_addr
|
|
}
|
|
|
|
# The LiteLLM secrets engine is managed through its own provider, which talks to
|
|
# the same Vault server. Token falls back to the VAULT_TOKEN environment variable.
|
|
provider "litellm" {
|
|
address = local.vault_addr
|
|
}
|
|
|
|
# The gpg secrets engine's keys are managed through its own provider (same Vault
|
|
# server; token falls back to VAULT_TOKEN).
|
|
provider "gpg" {
|
|
address = local.vault_addr
|
|
}
|
|
|
|
# The rancher token secrets engine is managed through its own provider (same
|
|
# Vault server; token falls back to VAULT_TOKEN).
|
|
provider "rancher" {
|
|
address = local.vault_addr
|
|
}
|
|
|
|
# The arrstack (arrproxy API key) secrets engine is managed through its own
|
|
# provider (same Vault server; token falls back to VAULT_TOKEN).
|
|
provider "arrstack" {
|
|
address = local.vault_addr
|
|
}
|
|
|
|
terraform {
|
|
backend "consul" {
|
|
address = "https://consul.service.consul"
|
|
path = "infra/terraform/vault/${path_relative_to_include()}/state"
|
|
scheme = "https"
|
|
lock = true
|
|
ca_file = "/etc/pki/tls/certs/ca-bundle.crt"
|
|
}
|
|
required_version = ">= 1.10"
|
|
required_providers {
|
|
vault = {
|
|
source = "hashicorp/vault"
|
|
version = "5.6.0"
|
|
}
|
|
consul = {
|
|
source = "hashicorp/consul"
|
|
version = "2.23.0"
|
|
}
|
|
litellm = {
|
|
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/litellmvaultsecret"
|
|
version = "0.1.0"
|
|
}
|
|
gpg = {
|
|
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/gpgvaultsecret"
|
|
version = "0.1.0"
|
|
}
|
|
rancher = {
|
|
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/ranchervaultsecret"
|
|
version = "0.1.0"
|
|
}
|
|
arrstack = {
|
|
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/vault-secrets-arrstack"
|
|
version = "0.2.0"
|
|
}
|
|
}
|
|
}
|
|
EOF
|
|
}
|