Skip to content

Terraform modules

The portal is backed by 9 no-code Terraform modules published to an HCP Terraform private registry. Each module handles one specific operation in the 4-layer onboarding model.

Module inventory

Admin layer (L0)

The following module bootstraps the tenant infrastructure that all other layers depend on:

Module Description
terraform-vault-hcptf-onboarding Bootstraps tenant onboarding into HCP Terraform and Vault namespaces

Trust layer (L1)

The following modules establish OIDC trust between Vault and external identity providers:

Module Description
terraform-vault-cluster-onboarding Creates a Vault JWT auth backend for Kubernetes/OpenShift cluster trust
terraform-vault-gitlab-onboarding Creates a Vault JWT auth backend for GitLab instance trust

Workload layer (L2)

The following modules register workload identities in Vault:

Module Description
terraform-vault-add-k8s-namespace-access Onboards a Kubernetes namespace/service account as a Vault workload identity
terraform-vault-add-gitlab-project-access Onboards a GitLab project as a Vault workload identity

Use-case layer (L3)

The following modules grant workloads access to specific secret types:

Module Description
terraform-vault-add-kvv2 Provisions KVv2 access and identity group bindings for a workload
terraform-vault-add-pgsql-role Provisions PostgreSQL static role access through Vault DB engine
terraform-vault-add-permission-group Grants custom ACL capabilities over Vault paths to workloads
terraform-vault-pgsql-onboarding Onboards PostgreSQL secrets engine and connection for downstream roles

Generating module docs

Module documentation is generated from terraform-docs output and the module README files:

make generate

This produces:

  • TechDocs sites under docs/<module>/ for the Backstage Docs tab
  • Variable inventories under generated/variables/<module>.json for the scaffolder