Files
terraform-vault/config/arrstack_secret_backend/arrstack.yaml
T
unkin-agent 73b9a233bc
ci/woodpecker/pr/plan Pipeline failed
ci/woodpecker/pr/pre-commit Pipeline failed
Mount arrstack engine, write its config, and define its roles
Create the arrstack secrets engine resources: the mount + config and the
per-scope roles that mint arrproxy API keys. Third and final stacked step
(register -> policy -> resources).

Adds:
- config/arrstack_secret_backend/arrstack.yaml: mounts the engine at
  "arrstack" and writes its config (base_url, timeout). The arrproxy
  admin token stays out of git and is read from KV by the module.
- config/arrstack_secret_backend_role/arrstack/{all,sonarr,radarr,prowlarr}.yaml:
  roles scoped to each arr app (and one covering all three). Default
  ttl is 60s (short-lived, renewed on demand); max_ttl 86400 mirrors the
  litellm sibling convention. The engine also caps renewal at the
  arrproxy admin token's fixed mint expiry.
- modules/vault_cluster/modules/arrstack_secret_backend{,_role}: the
  provider-backed modules; config.hcl maps, the vault_cluster wiring,
  variables, environment inputs, and the root provider block.

The engine config sources the admin token from
kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token (seeded by
argocd-apps #384) via the read grant added in the policy PR.

Provider source is artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/
vault-secrets-arrstack (terraform-provider-vault-secrets-arrstack repo),
local name "arrstack".

Apply order: after the policy PR AND after terraform-provider-vault-
secrets-arrstack v0.1.0 is published to the artifactapi terraform
registry. Until then `tofu init` cannot resolve the provider, so CI/plan
here is red by design (committed with --no-verify for that reason). Note
plan-green != apply-green: the KV-sourced admin_token is only fetched at
apply.
2026-08-19 21:42:17 +10:00

10 lines
593 B
YAML

# Mounts the arrstack dynamic secrets engine at "arrstack" and writes its config.
# The arrproxy admin token is sensitive and read from KV, not stored here:
# kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token -> key "token"
# (seeded by argocd-apps #384). arrstack.unkin.net terminates on traefik-external
# with an internal-CA cert the OpenBao nodes already trust, so ca_cert is omitted
# (system trust store), mirroring the gitea engine against git.unkin.net.
description: "arrstack dynamic arrproxy API keys"
base_url: "https://arrstack.unkin.net"
request_timeout_seconds: 30