unkin-agent b225ef6344
ci/woodpecker/pr/plan Pipeline failed
ci/woodpecker/pr/pre-commit Pipeline was successful
Add Authentik OIDC SSO as the default human login for OpenBao
Human access to OpenBao is LDAP-only today, so operators carry a second set of
credentials outside Authentik and group membership is maintained twice. This
makes Authentik SSO the offered default on the UI login page and gives
`bao login -method=oidc` a working CLI path, while approle and kubernetes (CI
and agents) plus the break-glass root path are untouched.

Add three modules mirroring the auth_ldap_* structure: auth_oidc_backend mounts
a vault_jwt_auth_backend of type oidc, auth_oidc_role creates the default login
role, and auth_oidc_group creates an external vault_identity_group plus its
group alias so IdP groups map onto policies.

Mount the backend at the literal path "oidc". The Authentik provider registers
strict redirect URIs containing /ui/vault/auth/oidc/oidc/callback, so the path
is load-bearing and must not be renamed.

Read client_id and client_secret from kv/service/authentik/oidc-vault, which
terraform-authentik generates and writes; nothing is seeded by hand.

Match groups on the ak_groups claim rather than groups, because Authentik's
default profile mapping only emits direct memberships and the estate nests
akP-* permission groups under akR-* roles.

Bind akP-vault-admin to global-root, the same policy the LDAP vault_admin group
already carries. Only akP-* permission groups are named in config or policy;
akR-* roles stay grouping-only.

Grant the deployer auth/oidc/* and identity group management, both of which it
currently lacks. AppRole capabilities are fixed at login, so these land in an
apply before the resources that need them.
2026-08-30 21:49:14 +10:00
2024-09-09 22:57:00 +10:00
2024-09-23 22:01:18 +10:00

terraform-vault

A repository to manage the configuration of Vault secret engines, authentication modes and policies.

Usage

  1. Initialize Terraform

Once you have your backend block configured, you need to initialize your Terraform working directory to configure the backend:

terraform init

This command initializes the backend and checks the connection to Consul. If everything is set up correctly, Terraform will start using Consul as its backend for storing the state.

  1. Common terraform init Errors

If you encounter errors while running terraform init, check the following:

Consul server is reachable: Make sure that the address is correct and that you can connect to the Consul server.
Consul token (if using ACLs): Verify that the token has the correct permissions to write to the specified path in the Consul KV store.
  1. Example Consul KV Structure

In Consul, the state file will be stored in the KV store under the specified path:

terraform/state

You can check the Consul KV store by accessing the Consul UI or using the consul kv command to see the stored Terraform state:

consul kv get terraform/state
S
Description
A repository to manage the configuration of Vault secret engines, authentication modes and policies.
Readme MIT 1.1 MiB
Languages
HCL 99.3%
Makefile 0.7%