9e7687fccb
ci/woodpecker/push/apply Pipeline was successful
## Why netbox_user_management authenticates to NetBox to reconcile service users + permissions on every apply. It must not depend on a second static admin token, and it must not break when the engine rotates its admin seed (`netbox/config/rotate` mints a fresh admin token and deletes the old one). The durable shape: keep exactly ONE static admin token, and have the netbox engine mint an ephemeral, user-admin-capable token that the e-breuninger provider uses to manage users. ## How - `module.netbox_user_mgmt_role` creates `netbox/roles/vault-user-mgmt`, a write-enabled role for a pre-existing NetBox superuser named by `user_mgmt_username`. Minted tokens authenticate AS that superuser (NetBox tokens carry no scope beyond `write_enabled`; the user's permissions apply), so they can create users. - `netbox_user_management` reads `netbox/creds/vault-user-mgmt` and configures the netbox provider with the minted token. When `user_mgmt_username` is unset it falls back to the single static `admin_token` (a `check` block warns that rotation would then break it) - a bootstrap/degraded path, never a second static token. - Grant the deployer `read` on `netbox/creds/vault-user-mgmt` (the one deliberate exception to the admin policy's `netbox/creds/*` exclusion). - Keep the bare-token + `token_version`-match postconditions on the single static admin token. ## Feasibility constraints (worked through, documented in-module) 1. **The engine CAN mint a user-admin token** - roles map to a pre-existing user with only a `write_enabled` gate (`vault-plugin-secrets-netbox` `path_roles.go`, `client.go` `MintToken`); point it at a superuser and minted tokens can manage users. 2. **Token transits state.** The hashicorp/vault provider (5.6.0) exposes ephemeral resources for KV only, not dynamic engine creds, so the mint is read via the `vault_generic_secret` DATA source: the short-lived token is written to state (sensitive, lease-revoked) and re-minted each plan. Migrate to an ephemeral resource once the vault provider ships a dynamic-secret one. 3. **A clean single fresh apply is not possible.** A provider cannot be configured from a role created in the same run (data sources don't defer; OpenTofu 1.11 defers only ephemeral resources, which the vault provider doesn't offer here). So enabling the dynamic path on a backend needs a one-time targeted bootstrap of the mount + role, then normal applies. Documented in `config/netbox_secret_backend/netbox.yaml`. ## Operator follow-up - Repair the live mount first (unchanged): `vault write netbox/config token=<BARE>` (the mount uses `ignore_changes=[token]`), keep `token_version=2`. - To enable dynamic minting: set `user_mgmt_username` to the pre-existing superuser, apply the deployer creds policy, then bootstrap once: `tofu apply -target=...netbox_secret_backend -target=...netbox_user_mgmt_role`, then apply normally. Until then user management stays on the static token (non-breaking, with a warning). Reviewed-on: #119 Co-authored-by: Ben Vincent <ben@unkin.net> Co-committed-by: Ben Vincent <ben@unkin.net>
486 lines
16 KiB
Terraform
486 lines
16 KiB
Terraform
variable "country" {
|
|
description = "Country identifier"
|
|
type = string
|
|
}
|
|
|
|
variable "region" {
|
|
description = "Region identifier"
|
|
type = string
|
|
}
|
|
|
|
variable "auth_approle_backend" {
|
|
description = "Map of AppRole auth backends to create"
|
|
type = map(object({
|
|
listing_visibility = optional(string)
|
|
default_lease_ttl = optional(string)
|
|
max_lease_ttl = optional(string)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "auth_approle_role" {
|
|
description = "Map of AppRole roles to create"
|
|
type = map(object({
|
|
approle_name = string
|
|
mount_path = string
|
|
token_ttl = optional(number)
|
|
token_max_ttl = optional(number)
|
|
bind_secret_id = optional(bool, false)
|
|
secret_id_ttl = optional(number)
|
|
token_bound_cidrs = optional(list(string), [])
|
|
alias_metadata = optional(map(string))
|
|
use_deterministic_role_id = optional(bool, true)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "auth_ldap_backend" {
|
|
description = "Map of LDAP auth backends to create"
|
|
type = map(object({
|
|
userdn = string
|
|
userattr = optional(string, "uid")
|
|
upndomain = optional(string)
|
|
discoverdn = optional(bool, false)
|
|
groupdn = optional(string)
|
|
groupfilter = optional(string)
|
|
groupattr = optional(string, "cn")
|
|
alias_metadata = optional(map(string))
|
|
username_as_alias = optional(bool, true)
|
|
listing_visibility = optional(string)
|
|
default_lease_ttl = optional(string)
|
|
max_lease_ttl = optional(string)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "auth_ldap_group" {
|
|
description = "Map of LDAP groups to create"
|
|
type = map(object({
|
|
groupname = string
|
|
backend = string
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "auth_kubernetes_backend" {
|
|
description = "Map of Kubernetes auth backends to create"
|
|
type = map(object({
|
|
kubernetes_host = string
|
|
disable_iss_validation = optional(bool, true)
|
|
use_annotations_as_alias_metadata = optional(bool, true)
|
|
listing_visibility = optional(string)
|
|
default_lease_ttl = optional(string)
|
|
max_lease_ttl = optional(string)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "auth_kubernetes_role" {
|
|
description = "Map of Kubernetes auth roles to create"
|
|
type = map(object({
|
|
role_name = string
|
|
backend = string
|
|
bound_service_account_names = list(string)
|
|
bound_service_account_namespaces = list(string)
|
|
token_ttl = optional(number, 3600)
|
|
token_max_ttl = optional(number, 86400)
|
|
audience = optional(string, "vault")
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "kv_secret_backend" {
|
|
description = "Map of KV secret engines to create"
|
|
type = map(object({
|
|
type = optional(string, "kv-v2")
|
|
description = optional(string)
|
|
version = optional(string, "2")
|
|
max_versions = optional(number)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "transit_secret_backend" {
|
|
description = "Map of Transit secret engines to create"
|
|
type = map(object({
|
|
description = optional(string)
|
|
default_lease_ttl_seconds = optional(number, 3600)
|
|
max_lease_ttl_seconds = optional(number, 86400)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "transit_secret_backend_key" {
|
|
description = "Map of Transit keys to create"
|
|
type = map(object({
|
|
name = string
|
|
backend = string
|
|
type = optional(string, "aes256-gcm96")
|
|
deletion_allowed = optional(bool, false)
|
|
derived = optional(bool, false)
|
|
exportable = optional(bool, false)
|
|
allow_plaintext_backup = optional(bool, false)
|
|
auto_rotate_period = optional(string)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "ssh_secret_backend" {
|
|
description = "Map of SSH secret engines to create"
|
|
type = map(object({
|
|
description = optional(string)
|
|
max_lease_ttl_seconds = optional(number, 315360000)
|
|
generate_signing_key = optional(bool)
|
|
key_type = optional(string, "ssh-rsa")
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "ssh_secret_backend_role" {
|
|
description = "Map of SSH roles to create"
|
|
type = map(object({
|
|
name = string
|
|
backend = string
|
|
key_type = optional(string, "ca")
|
|
algorithm_signer = optional(string, "rsa-sha2-256")
|
|
ttl = optional(number, 315360000)
|
|
allow_host_certificates = optional(bool, false)
|
|
allow_user_certificates = optional(bool, false)
|
|
allowed_domains = optional(string)
|
|
allow_subdomains = optional(bool, false)
|
|
allow_bare_domains = optional(bool, false)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "pki_secret_backend" {
|
|
description = "Map of PKI secret engines to create"
|
|
type = map(object({
|
|
description = optional(string)
|
|
max_lease_ttl_seconds = optional(number, 315360000)
|
|
common_name = string
|
|
issuer_name = string
|
|
ttl = optional(number, 315360000)
|
|
format = optional(string, "pem")
|
|
issuing_certificates = optional(list(string), [])
|
|
crl_distribution_points = optional(list(string), [])
|
|
ocsp_servers = optional(list(string), [])
|
|
enable_templating = optional(bool, false)
|
|
default_follows_latest_issuer = optional(bool, false)
|
|
crl_expiry = optional(string, "72h")
|
|
crl_disable = optional(bool, false)
|
|
ocsp_disable = optional(bool, false)
|
|
auto_rebuild = optional(bool, false)
|
|
enable_delta = optional(bool, false)
|
|
delta_rebuild_interval = optional(string)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "pki_secret_backend_role" {
|
|
description = "Map of PKI roles to create"
|
|
type = map(object({
|
|
name = string
|
|
backend = string
|
|
allow_ip_sans = optional(bool, false)
|
|
allowed_domains = optional(list(string), [])
|
|
allow_subdomains = optional(bool, false)
|
|
allow_glob_domains = optional(bool, false)
|
|
allow_bare_domains = optional(bool, false)
|
|
enforce_hostnames = optional(bool, false)
|
|
allow_any_name = optional(bool, false)
|
|
max_ttl = optional(number)
|
|
key_bits = optional(number, 4096)
|
|
country = optional(list(string), [])
|
|
use_csr_common_name = optional(bool, false)
|
|
use_csr_sans = optional(bool, false)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "pki_mount_only" {
|
|
description = "Map of PKI mounts to create (without certificate generation)"
|
|
type = map(object({
|
|
description = optional(string)
|
|
max_lease_ttl_seconds = optional(number, 315360000)
|
|
issuing_certificates = optional(list(string), [])
|
|
crl_distribution_points = optional(list(string), [])
|
|
ocsp_servers = optional(list(string), [])
|
|
enable_templating = optional(bool, false)
|
|
default_issuer_ref = optional(string)
|
|
default_follows_latest_issuer = optional(bool, false)
|
|
crl_expiry = optional(string, "72h")
|
|
crl_disable = optional(bool, false)
|
|
ocsp_disable = optional(bool, false)
|
|
auto_rebuild = optional(bool, false)
|
|
enable_delta = optional(bool, false)
|
|
delta_rebuild_interval = optional(string)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "consul_secret_backend" {
|
|
description = "Map of Consul secret engines to create"
|
|
type = map(object({
|
|
description = optional(string)
|
|
address = string
|
|
bootstrap = optional(bool, false)
|
|
bootstrap_token = optional(string)
|
|
scheme = optional(string, "https")
|
|
ca_cert = optional(string)
|
|
client_cert = optional(string)
|
|
client_key = optional(string)
|
|
default_lease_ttl_seconds = optional(number)
|
|
max_lease_ttl_seconds = optional(number)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "consul_secret_backend_role" {
|
|
description = "Map of Consul roles to create"
|
|
type = map(object({
|
|
name = string
|
|
backend = string
|
|
consul_roles = optional(list(string), [])
|
|
ttl = optional(number)
|
|
max_ttl = optional(number)
|
|
local = optional(bool, false)
|
|
datacenters = optional(list(string))
|
|
description = optional(string)
|
|
service_identities = optional(list(object({
|
|
service_name = string
|
|
datacenters = optional(list(string))
|
|
})))
|
|
node_identities = optional(list(object({
|
|
node_name = string
|
|
datacenter = string
|
|
})))
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "consul_backend_aliases" {
|
|
description = "Map of consul backend names to sanitized provider aliases"
|
|
type = map(string)
|
|
default = {}
|
|
}
|
|
|
|
variable "kubernetes_secret_backend" {
|
|
description = "Map of Kubernetes secret engines to create"
|
|
type = map(object({
|
|
description = optional(string)
|
|
default_lease_ttl_seconds = optional(number, 600)
|
|
max_lease_ttl_seconds = optional(number, 86400)
|
|
kubernetes_host = string
|
|
disable_local_ca_jwt = optional(bool, false)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "kubernetes_secret_backend_role" {
|
|
description = "Map of Kubernetes secret backend roles to create"
|
|
type = map(object({
|
|
name = string
|
|
backend = string
|
|
allowed_kubernetes_namespaces = optional(list(string), ["*"])
|
|
kubernetes_role_type = optional(string, "Role")
|
|
extra_labels = optional(map(string), {})
|
|
service_account_name = optional(string)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "litellm_secret_backend" {
|
|
description = "Map of LiteLLM secret engines to create (mount + config). The master key is read from KV"
|
|
type = map(object({
|
|
plugin = optional(string, "vault-plugin-secrets-litellm")
|
|
description = optional(string)
|
|
base_url = string
|
|
request_timeout_seconds = optional(number, 30)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "litellm_secret_backend_role" {
|
|
description = "Map of LiteLLM roles to create"
|
|
type = map(object({
|
|
name = string
|
|
backend = string
|
|
models = optional(list(string))
|
|
max_budget = optional(number)
|
|
key_alias_prefix = optional(string)
|
|
ttl = optional(number)
|
|
max_ttl = optional(number)
|
|
metadata = optional(map(string))
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "plugins" {
|
|
description = "Map of plugins to import (register) in the catalog, keyed by catalog name"
|
|
type = map(object({
|
|
name = string
|
|
type = optional(string, "secret")
|
|
command = optional(string)
|
|
sha256 = string
|
|
version = optional(string)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "gpg_secret_backend" {
|
|
description = "Map of GPG/OpenPGP secret engines to mount (path => registered plugin + description). The plugin is registered separately via config/plugins."
|
|
type = map(object({
|
|
plugin = optional(string, "vault-plugin-secrets-gpg")
|
|
description = optional(string)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "gpg_key" {
|
|
description = "Map of OpenPGP keys to manage in a gpg engine mount"
|
|
type = map(object({
|
|
name = string
|
|
backend = string
|
|
algorithm = optional(string, "rsa-3072")
|
|
identity = optional(string)
|
|
exportable = optional(bool, false)
|
|
deletion_allowed = optional(bool, false)
|
|
min_decryption_version = optional(number)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "rancher_secret_backend" {
|
|
description = "Map of rancher token secret engines to create (mount + config)"
|
|
type = map(object({
|
|
plugin = optional(string, "vault-plugin-secrets-rancher")
|
|
description = optional(string)
|
|
rancher_url = string
|
|
ca_cert = optional(string)
|
|
tls_skip_verify = optional(bool, false)
|
|
request_timeout_seconds = optional(number, 30)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "rancher_secret_backend_service_account" {
|
|
description = "Map of seeded, auto-rotated rancher service-account tokens (seed token read from KV)"
|
|
type = map(object({
|
|
name = string
|
|
backend = string
|
|
token_ttl = optional(number)
|
|
rotation_period = optional(number)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "rancher_secret_backend_role" {
|
|
description = "Map of rancher token-minting roles to create"
|
|
type = map(object({
|
|
name = string
|
|
backend = string
|
|
service_account = string
|
|
cluster_name = optional(string)
|
|
description = optional(string)
|
|
ttl = optional(number)
|
|
max_ttl = optional(number)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "gitea_secret_backend" {
|
|
description = "Map of gitea token secret engines to create (mount + config; seeded admin creds read from KV)"
|
|
type = map(object({
|
|
plugin = optional(string, "vault-plugin-secrets-gitea")
|
|
description = optional(string)
|
|
gitea_url = string
|
|
ca_cert = optional(string)
|
|
tls_skip_verify = optional(bool, false)
|
|
request_timeout_seconds = optional(number, 30)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "gitea_secret_backend_role" {
|
|
description = "Map of gitea token-minting roles to create"
|
|
type = map(object({
|
|
name = string
|
|
backend = string
|
|
username = string
|
|
scopes = list(string)
|
|
token_name_prefix = optional(string)
|
|
ttl = optional(number)
|
|
max_ttl = optional(number)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "netbox_secret_backend" {
|
|
description = "Map of netbox token secret engines to create (mount + config; seeded admin token read from KV)"
|
|
type = map(object({
|
|
plugin = optional(string, "vault-plugin-secrets-netbox")
|
|
description = optional(string)
|
|
netbox_url = string
|
|
token_version = optional(number, 2)
|
|
ca_cert = optional(string)
|
|
tls_skip_verify = optional(bool, false)
|
|
request_timeout_seconds = optional(number, 30)
|
|
# Pre-existing NetBox superuser (or add_user + add_token + grant_token) the
|
|
# engine mints an ephemeral user-admin token for, so netbox_user_management
|
|
# authenticates with a Vault-minted credential derived from the single static
|
|
# admin token instead of a second static one. Unset = use the static
|
|
# admin_token directly (bootstrap/degraded; breaks after admin-token rotation).
|
|
user_mgmt_username = optional(string)
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "netbox_secret_backend_role" {
|
|
description = "Map of netbox engine roles; each role's filename-derived name is both the engine role and the NetBox username it mints tokens for, and its permissions block is the user's object-permission set"
|
|
type = map(object({
|
|
name = string
|
|
backend = string
|
|
netbox_username = optional(string)
|
|
netbox_user_id = optional(number)
|
|
write_enabled = optional(bool, false)
|
|
description = optional(string)
|
|
ttl = optional(number)
|
|
max_ttl = optional(number)
|
|
active = optional(bool, true)
|
|
staff = optional(bool, false)
|
|
email = optional(string)
|
|
permissions = optional(list(object({
|
|
name = optional(string)
|
|
object_types = list(string)
|
|
actions = optional(list(string), ["view", "add", "change", "delete"])
|
|
constraints = optional(string)
|
|
description = optional(string)
|
|
enabled = optional(bool, true)
|
|
})), [])
|
|
}))
|
|
default = {}
|
|
}
|
|
|
|
variable "netbox_backend_aliases" {
|
|
description = "Map of netbox backend names to sanitized provider aliases"
|
|
type = map(string)
|
|
default = {}
|
|
}
|
|
|
|
variable "policy_auth_map" {
|
|
description = "Map of auth mounts -> auth roles -> policy names"
|
|
type = map(map(list(string)))
|
|
default = {}
|
|
}
|
|
|
|
variable "policy_rules_map" {
|
|
description = "Map of policy names to their rules"
|
|
type = map(list(object({
|
|
path = string
|
|
capabilities = list(string)
|
|
})))
|
|
default = {}
|
|
}
|
|
|