890d666a53
ci/woodpecker/push/apply Pipeline was successful
Nothing stopped a policy under policies/x/y/ from granting a rule path outside its own directory, so an over-broad grant read as ordinary review noise and only surfaced once applied to Vault. - add tests/test_policies.py: a pydantic model rejecting unknown keys, empty rules and non-Vault capabilities - check every rule path segment-wise against the policy's own directory, stripping the kv-v2 data/metadata segment - relocate the rules that reached outside their directory, carrying capabilities and auth bindings verbatim - run the suite from a local pre-commit hook and from make test Reviewed-on: #158 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
39 lines
1.3 KiB
Makefile
39 lines
1.3 KiB
Makefile
.PHONY: init plan apply format test
|
|
|
|
VAULT_AUTH_METHOD ?= approle
|
|
VAULT_K8S_ROLE ?= woodpecker_terraform_vault
|
|
VAULT_K8S_MOUNT ?= auth/k8s/au/syd1
|
|
VAULT_K8S_JWT_PATH ?= /var/run/secrets/kubernetes.io/serviceaccount/token
|
|
|
|
# Define vault_env function to set up vault environment
|
|
define vault_env
|
|
@export VAULT_ADDR="https://vault.service.consul:8200" && \
|
|
if [ "$(VAULT_AUTH_METHOD)" = "kubernetes" ]; then \
|
|
export VAULT_TOKEN=$$(vault write -field=token $(VAULT_K8S_MOUNT)/login role=$(VAULT_K8S_ROLE) jwt=$$(cat $(VAULT_K8S_JWT_PATH))); \
|
|
else \
|
|
export VAULT_TOKEN=$$(vault write -field=token auth/approle/login role_id=$$VAULT_ROLEID); \
|
|
fi && \
|
|
export CONSUL_HTTP_TOKEN=$$(vault read -field=token consul_root/au/syd1/creds/terraform-vault)
|
|
endef
|
|
|
|
init:
|
|
@$(call vault_env) && \
|
|
terragrunt run --all --non-interactive init -- -upgrade
|
|
|
|
plan: init
|
|
@$(call vault_env) && \
|
|
terragrunt run --all --parallelism 4 --non-interactive plan -- -lock=false
|
|
|
|
apply: init
|
|
@$(call vault_env) && \
|
|
terragrunt run --all --parallelism 2 --non-interactive apply
|
|
|
|
test:
|
|
@uv run --with pyyaml --with pydantic python -m unittest discover -s tests -t .
|
|
|
|
format:
|
|
@echo "Formatting OpenTofu files..."
|
|
@tofu fmt -recursive .
|
|
@echo "Formatting Terragrunt files..."
|
|
@terragrunt hcl fmt
|