Skip to content

terraform-vault-add-gitlab-project-access

Workload-layer module that onboards one GitLab project as a Vault identity entity, alias, and JWT login role.

Layer

Workload. This module creates identity and login, but no secret policy grants.

Prerequisites

  • GitLab trust module already provisioned (terraform-vault-gitlab-onboarding) for the same gitlab_instance_name
  • Stable GitLab project_id and project_path values

Discovered values

This module no longer takes the trust mount path or accessor as inputs. Both are resolved from gitlab_instance_name:

  • jwt_auth_path is derived as jwt-gitlab/<gitlab_instance_name>, matching the path the trust module mounts.
  • The JWT mount accessor is discovered at plan time with the vault_auth_backend data source on that path.

Inputs

Name Type Description
gitlab_instance_name string One of cloud, dedicated-prod, dedicated-dev
workload_name string Workload identifier, regex validated
gitlab_project_id string Stable project ID used as alias name
gitlab_project_path string Bound claim value (group/project)
bound_audience string JWT audience for Vault authentication, default "vault"
token_ttl number JWT role TTL in seconds, default 3600
token_max_ttl number JWT role max TTL in seconds, default 86400

Outputs

Name Description
entity_id Entity ID for downstream use-case modules
auth_role_name JWT role name used by pipeline login
gitlab_instance_name Echo
workload_name Echo

No-code notes

  • Alias and user_claim use stable project_id.
  • token_policies on the workload login role is intentionally empty.
  • Policy grants are attached later through use-case identity groups.

No-code provisioning

This module is no-code enabled in the hc-ric-demo private registry (pinned to 0.3.0). Click Provision workspace, pick a project and workspace name, then complete the form. gitlab_instance_name is presented as a dropdown limited to cloud, dedicated-prod, dedicated-dev. The trust mount path and accessor are derived from gitlab_instance_name, so they are no longer form fields.

No-code UX note: The gitlab_instance_name dropdown is driven by explicit no-code variable-options configured on the module in the registry, not by the module’s contains() validation (which only validates on submit). These options (cloud, dedicated-prod, dedicated-dev) are a registry-side setting applied using the tfe_no_code_module resource or the no-code modules API. They are not stored in this repository, so re-enabling no-code provisioning for the module requires re-applying them.

Form fields:

Field Required Notes
gitlab_instance_name yes Dropdown: cloud / dedicated-prod / dedicated-dev
workload_name yes Workload identifier
gitlab_project_id yes Numeric project ID
gitlab_project_path yes group/project claim

Registry usage

module "add_gitlab_project" {
  source  = "app.terraform.io/<org>/add-gitlab-project-access/vault"
  version = "~> 0.3.0"

  gitlab_instance_name = "cloud"
  workload_name        = "billing-ci"
  gitlab_project_id    = "48261734"
  gitlab_project_path  = "group/billing-service"
  bound_audience       = "https://vault.example.com"
}

Next step in chain: use-case modules consume entity_id.


Terraform reference (generated)

Generated by make generate from terraform-vault-onboarding/terraform-vault-add-gitlab-project-access. Do not edit by hand.

Requirements

Name Version
terraform >= 1.9
vault ~> 5.10

Providers

Name Version
vault 5.10.1

Modules

No modules.

Resources

Name Type
vault_identity_entity.this resource
vault_identity_entity_alias.this resource
vault_jwt_auth_backend_role.this resource
vault_auth_backend.gitlab data source

Inputs

Name Description Type Default Required
bound_audience JWT audience for Vault authentication. string "vault" no
gitlab_instance_name GitLab instance scope used in trust mount naming. Must match the gitlab_instance_name used in the gitlab-onboarding trust module. string n/a yes
gitlab_project_id GitLab project numeric ID used as stable alias name and user claim. string n/a yes
gitlab_project_path GitLab project path (group/project) used in bound_claims. string n/a yes
token_max_ttl JWT login role token max TTL in seconds. number 86400 no
token_ttl JWT login role token TTL in seconds. number 3600 no
workload_name Short workload identifier used in entity and role naming. string n/a yes

Outputs

Name Description
auth_role_name JWT login role name used by GitLab pipeline login.
entity_id Vault identity entity ID to be passed to use-case modules.
gitlab_instance_name Echo of gitlab_instance_name input.
workload_name Echo of workload_name input.