Files
terraform-vault/config/ssh_secret_backend_role
unkin-agent b576524553
ci/woodpecker/push/apply Pipeline was successful
Accept IP and short-hostname principals on sshca/signhost (#155)
Puppet signs host certs with principals hostname, FQDN and IP (plus extra IPs on k8s nodes). The signhost role only matched allowed_domains entries exactly or by suffix, so every agent run failed with `198.18.29.56 is not a valid value for valid_principals`.

- Set `allowed_domains` on `sshca/signhost` to `*`, the only value OpenBao treats as unrestricted for host principals (per-entry globs are not honoured).
- Note the sole-entry requirement in the config.

Role stays host-only (`allow_user_certificates: false`); the CA key is untouched.

Reviewed-on: #155
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-24 22:26:55 +10:00
..