Initial commit
terraform / check (push) Canceled after 0s

This commit is contained in:
stolzor committed 2026-10-11 20:30:21 +03:00
commit 64be99308b
53 files changed
+1983

No files matched your search

+23
View File
@@ -0,0 +1,23 @@
# This file is maintained automatically by "terraform init".
# Manual edits may be lost in future updates.
provider "registry.terraform.io/hashicorp/vault" {
version = "5.12.0"
constraints = "5.12.0"
hashes = [
"h1:NXnrOFre4t8nj7+ZQ3MKIECpDohjMBtHWm2aen75nfU=",
"zh:0683ab1870c6ffe78463465fc0954ff18fbbfe16d79dc121e20efb27cd2be850",
"zh:0ade50207774b544995066be02cf7e108abe828e089eb646da4c04863cbee702",
"zh:2b3360bec8d457a7d19df86bf4576711035785928a9fa307affce10cbeae89fd",
"zh:5317888b0e3547341b8434f42bbb8df2d30bdd95cc1bde9a4c7a80d266fe9f6b",
"zh:6c0271736ceb08774bebedf424735d92c4fe33b8e4db371cc027cbded0439a2e",
"zh:70bb990d22d1ce1ceac2209aee025e0f7deab48d95002aa2b8360d9c86343ea8",
"zh:78d5eefdd9e494defcb3c68d282b8f96630502cac21d1ea161f53cfe9bb483b3",
"zh:7f33d7bbf145e15542cfc6b1dbeed639d08204802c239c098770c5f507d1e59c",
"zh:8ae8ca31d3c9e4b530c80eed12d8debe6fc46b407acb469b33247227aaafbf51",
"zh:c61fcc4d714cefee0696e2f8bf715b5826099e405f66acc859e496de688b6a8e",
"zh:ceca8db980ae3bd986142903487d75d143edfc5c7cf467da38f3698f717db046",
"zh:e1bba3cb6a728e9bf2951139f1e7bae5bec37a37cd4bfebe282e306212a62c4c",
"zh:f9765b4aa90e9e4eae03626ebfdfeda54954ec2552267aedce1fb2643f6eb2de",
]
}
+9
View File
@@ -0,0 +1,9 @@
locals {
config = yamldecode(file("${path.root}/../config.yaml"))
}
module "config" {
source = "../modules/config"
infra = local.config.infra
services = local.config.services
}
+75
View File
@@ -0,0 +1,75 @@
resource "vault_mount" "secret" {
path = module.config.vault.mount
type = "kv"
options = {
version = "2"
}
}
resource "vault_policy" "service" {
for_each = module.config.services
name = "service-${each.key}"
policy = jsonencode({
path = {
"${vault_mount.secret.path}/data/${each.key}/*" = {
capabilities = ["read"]
}
"${module.config.vault.database_mount}/creds/${each.key}" = {
capabilities = ["read"]
}
}
})
}
resource "vault_auth_backend" "approle" {
type = "approle"
}
resource "vault_approle_auth_backend_role" "service" {
for_each = module.config.services
backend = vault_auth_backend.approle.path
role_name = each.key
token_policies = [vault_policy.service[each.key].name]
token_ttl = 3600
token_max_ttl = 14400
secret_id_ttl = 2592000
}
locals {
kv = vault_mount.secret.path
db = module.config.vault.database_mount
ar = vault_auth_backend.approle.path
manage = ["create", "read", "update", "delete"]
}
resource "vault_policy" "terraform" {
name = "terraform"
policy = jsonencode({
path = {
"auth/token/create" = { capabilities = ["update"] }
"sys/mounts/${local.kv}" = { capabilities = ["read"] }
"sys/mounts/auth/${local.ar}" = { capabilities = ["read"] }
"sys/mounts/auth/${local.ar}/tune" = { capabilities = ["read"] }
"sys/policies/acl/service-*" = { capabilities = local.manage }
"sys/policies/acl/terraform" = { capabilities = ["read", "update"] }
"auth/${local.ar}/role/+" = { capabilities = local.manage }
"auth/${local.ar}/role/+/role-id" = { capabilities = ["read"] }
"auth/${local.ar}/role/+/secret-id" = { capabilities = ["update"] }
"${local.kv}/data/+/s3" = { capabilities = local.manage }
"${local.kv}/data/+/postgres" = { capabilities = local.manage }
"${local.kv}/metadata/+/s3" = { capabilities = ["read", "update", "delete"] }
"${local.kv}/metadata/+/postgres" = { capabilities = ["read", "update", "delete"] }
"sys/mounts/${local.db}" = { capabilities = ["read"] }
"sys/mounts/${local.db}/tune" = { capabilities = ["update"] }
"${local.db}/config" = { capabilities = ["list"] }
"${local.db}/config/postgres" = { capabilities = ["read", "update"] }
"${local.db}/roles/+" = { capabilities = local.manage }
"sys/storage/raft/snapshot" = { capabilities = ["read"] }
}
})
}
+4
View File
@@ -0,0 +1,4 @@
output "approle_role_ids" {
value = { for name, role in vault_approle_auth_backend_role.service : name => role.role_id }
description = "role_id of the services, secret_id is issued separately"
}
+4
View File
@@ -0,0 +1,4 @@
provider "vault" {
address = module.config.vault.address
token = var.vault_token
}
+5
View File
@@ -0,0 +1,5 @@
variable "vault_token" {
description = "vault token"
type = string
sensitive = true
}
+11
View File
@@ -0,0 +1,11 @@
terraform {
required_providers {
vault = {
source = "hashicorp/vault"
version = "5.12.0"
}
}
backend "s3" {
key = "vault/terraform.tfstate"
}
}