31424ea6ff
ci/woodpecker/push/apply Pipeline was successful
## Why CI installs vault by shelling out to `dnf install vault -y`. That reads metadata for every enabled repo (appstream/baseos/crb/epel/ha) and downloads the 169MB vendored vault RPM from the `unkin` repo on **every** plan/apply run (~39s per job measured in `almalinux9-opentofu:20260606`). ## Change - Replace `dnf install vault -y` with a pinned `curl` of the upstream vault zip from the artifactapi `hashicorp-releases` remote proxy, extracted with the image's `python3` (`python3 -m zipfile`) to `/usr/local/bin/vault`. - Pin the version via a new `VAULT_VERSION` env var (`1.20.0`); bump the var to upgrade. ## Speedup Measured in `git.unkin.net/unkin/almalinux9-opentofu:20260606`: | approach | time | |---|---| | `dnf install vault -y` (current) | ~39s | | `dnf --disablerepo='*' --enablerepo=unkin` (still pulls 169MB RPM) | ~9s | | curl zip from artifactapi + python extract (this PR) | ~6.6s | ~32s saved per plan/apply job. The zip is cached by artifactapi after first fetch (warm ~3s). ## Caveats - Assumes the `almalinux9-opentofu` image ships `curl` + `python3` (both present in `:20260606`). - Relies on the existing artifactapi `hashicorp-releases` generic remote whose patterns already allow `vault/.*vault_.*_linux_amd64.zip`. --------- Co-authored-by: benvin <neotheo@gmail.com> Reviewed-on: #99 Co-authored-by: Ben Vincent <ben@unkin.net> Co-committed-by: Ben Vincent <ben@unkin.net>