5084a53015
ci/woodpecker/push/apply Pipeline was successful
Why: step 3 of the ordered ghp plugin add — register vault-plugin-secrets-ghp in the OpenBao plugin catalog as its own atomic change, before the engine is mounted/configured. How: add config/plugins/vault-plugin-secrets-ghp.yaml (type: secret; sha256 pins the v0.1.0 binary installed by puppet-prod#520). config/plugins/* is generically discovered by config.hcl, so this is the only file. Catalog import is covered by the shared sudo-protected sys/plugins/catalog grant. Order: puppet-prod#520 (install) -> terraform-vault#122 (config-write policy, merged) -> **this** (catalog) -> terraform-vault#121 (mount + config + role). Reviewed-on: #123 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
12 lines
544 B
YAML
12 lines
544 B
YAML
# config/plugins/vault-plugin-secrets-ghp.yaml
|
|
# Imports (registers) the ghp secrets plugin in the catalog. Filename =
|
|
# catalog name = mount type. The binary is installed on the OpenBao nodes by
|
|
# Puppet (openbao-plugin-secrets-ghp RPM ->
|
|
# /opt/openbao-plugins/vault-plugin-secrets-ghp).
|
|
#
|
|
# sha256 pins the released v0.1.0 binary; bump it in lockstep with any RPM
|
|
# upgrade or OpenBao will refuse to launch the plugin.
|
|
type: secret
|
|
command: vault-plugin-secrets-ghp
|
|
sha256: "85761421cd532788ed28fb57e93d3868f3577320a538289936d9ed3be5f396de"
|