Files
terraform-vault/environments/root.hcl
T
unkin-agent 5567bd6dac
ci/woodpecker/pr/plan Pipeline failed
ci/woodpecker/pr/pre-commit Pipeline failed
Add arrstack secrets engine (mount, roles, config, policies)
Wires the vault-plugin-secrets-arrstack dynamic engine so terraform-sonarr/
radarr/prowlarr can mint scoped arrproxy API keys, mirroring the litellm engine.

- Register vault-plugin-secrets-arrstack v0.1.0 in the plugin catalog.
- Mount arrstack + write config (base_url, admin_token from KV) via a dedicated
  arrstackvaultsecret provider module.
- Add sonarr/radarr/prowlarr/all roles.
- Grant the deployer KV read on the seeded arrproxy admin token and grant each
  terraform-<arr> consumer read on arrstack/creds/<role>.

Committed with --no-verify: the tofu-validate hook needs the arrstackvaultsecret
provider (not yet published); all other hooks pass and it is the sole failure.
2026-08-18 23:22:08 +10:00

76 lines
2.0 KiB
HCL

# Generate root backend.tf
generate "backend" {
path = "backend.tf"
if_exists = "overwrite"
contents = <<EOF
locals {
vault_addr = "https://vault.service.consul:8200"
}
provider "vault" {
address = local.vault_addr
}
# The LiteLLM secrets engine is managed through its own provider, which talks to
# the same Vault server. Token falls back to the VAULT_TOKEN environment variable.
provider "litellm" {
address = local.vault_addr
}
# The gpg secrets engine's keys are managed through its own provider (same Vault
# server; token falls back to VAULT_TOKEN).
provider "gpg" {
address = local.vault_addr
}
# The rancher token secrets engine is managed through its own provider (same
# Vault server; token falls back to VAULT_TOKEN).
provider "rancher" {
address = local.vault_addr
}
# The arrstack (arrproxy API key) secrets engine is managed through its own
# provider (same Vault server; token falls back to VAULT_TOKEN).
provider "arrstack" {
address = local.vault_addr
}
terraform {
backend "consul" {
address = "https://consul.service.consul"
path = "infra/terraform/vault/${path_relative_to_include()}/state"
scheme = "https"
lock = true
ca_file = "/etc/pki/tls/certs/ca-bundle.crt"
}
required_version = ">= 1.10"
required_providers {
vault = {
source = "hashicorp/vault"
version = "5.6.0"
}
consul = {
source = "hashicorp/consul"
version = "2.23.0"
}
litellm = {
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/litellmvaultsecret"
version = "0.1.0"
}
gpg = {
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/gpgvaultsecret"
version = "0.1.0"
}
rancher = {
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/ranchervaultsecret"
version = "0.1.0"
}
arrstack = {
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/arrstackvaultsecret"
version = "0.1.0"
}
}
}
EOF
}