c46641dafb
Vault/OpenBao secrets engine managing Rancher API tokens via the public tokens.ext.cattle.io API. - config: Rancher connection (URL + TLS) - service-accounts/<name>: seeded root tokens, auto-rotated before Rancher's TTL cap via a PeriodicFunc (default 45d rotation, 90d token TTL); the current token mints its own replacement. Manual /rotate endpoint too. - roles/<name>: mint policy referencing a service account; cluster_name + TTL scoping (Rancher tokens inherit the seeding user's RBAC). - creds/<role>: dynamic, lease-bound tokens deleted from Rancher on revoke. Ports the bind-tsig Woodpecker RPM release, nfpm packaging, and a mock-Rancher e2e (Vault + OpenBao). Unit tests cover the full lifecycle.
5 lines
184 B
Cheetah
Executable File
5 lines
184 B
Cheetah
Executable File
#!/usr/bin/env bash
|
|
# Ensure the plugin directory exists before the binary is laid down.
|
|
# Rendered per flavour via envsubst (see scripts/build-rpm.sh).
|
|
mkdir -p ${PACKAGE_PLUGIN_DIR}
|