terraform-vault-add-gitlab-project-access¶
Workload-layer module that onboards one GitLab project as a Vault identity entity, alias, and JWT login role.
Layer¶
Workload. This module creates identity and login, but no secret policy grants.
Prerequisites¶
- GitLab trust module already provisioned (
terraform-vault-gitlab-onboarding) for the samegitlab_instance_name - Stable GitLab
project_idandproject_pathvalues
Discovered values¶
This module no longer takes the trust mount path or accessor as inputs. Both are resolved from gitlab_instance_name:
jwt_auth_pathis derived asjwt-gitlab/<gitlab_instance_name>, matching the path the trust module mounts.- The JWT mount accessor is discovered at plan time with the
vault_auth_backenddata source on that path.
Inputs¶
| Name | Type | Description |
|---|---|---|
gitlab_instance_name |
string |
One of cloud, dedicated-prod, dedicated-dev |
workload_name |
string |
Workload identifier, regex validated |
gitlab_project_id |
string |
Stable project ID used as alias name |
gitlab_project_path |
string |
Bound claim value (group/project) |
bound_audience |
string |
JWT audience for Vault authentication, default "vault" |
token_ttl |
number |
JWT role TTL in seconds, default 3600 |
token_max_ttl |
number |
JWT role max TTL in seconds, default 86400 |
Outputs¶
| Name | Description |
|---|---|
entity_id |
Entity ID for downstream use-case modules |
auth_role_name |
JWT role name used by pipeline login |
gitlab_instance_name |
Echo |
workload_name |
Echo |
No-code notes¶
- Alias and
user_claimuse stableproject_id. token_policieson the workload login role is intentionally empty.- Policy grants are attached later through use-case identity groups.
No-code provisioning¶
This module is no-code enabled in the hc-ric-demo private registry (pinned to 0.3.0). Click Provision workspace, pick a project and workspace name, then complete the form. gitlab_instance_name is presented as a dropdown limited to cloud, dedicated-prod, dedicated-dev. The trust mount path and accessor are derived from gitlab_instance_name, so they are no longer form fields.
No-code UX note: The
gitlab_instance_namedropdown is driven by explicit no-codevariable-optionsconfigured on the module in the registry, not by the module’scontains()validation (which only validates on submit). These options (cloud,dedicated-prod,dedicated-dev) are a registry-side setting applied using thetfe_no_code_moduleresource or the no-code modules API. They are not stored in this repository, so re-enabling no-code provisioning for the module requires re-applying them.
Form fields:
| Field | Required | Notes |
|---|---|---|
gitlab_instance_name |
yes | Dropdown: cloud / dedicated-prod / dedicated-dev |
workload_name |
yes | Workload identifier |
gitlab_project_id |
yes | Numeric project ID |
gitlab_project_path |
yes | group/project claim |
Registry usage¶
module "add_gitlab_project" {
source = "app.terraform.io/<org>/add-gitlab-project-access/vault"
version = "~> 0.3.0"
gitlab_instance_name = "cloud"
workload_name = "billing-ci"
gitlab_project_id = "48261734"
gitlab_project_path = "group/billing-service"
bound_audience = "https://vault.example.com"
}
Next step in chain: use-case modules consume entity_id.
Terraform reference (generated)¶
Generated by make generate from terraform-vault-onboarding/terraform-vault-add-gitlab-project-access. Do not edit by hand.
Requirements¶
| Name | Version |
|---|---|
| terraform | >= 1.9 |
| vault | ~> 5.10 |
Providers¶
| Name | Version |
|---|---|
| vault | 5.10.1 |
Modules¶
No modules.
Resources¶
| Name | Type |
|---|---|
| vault_identity_entity.this | resource |
| vault_identity_entity_alias.this | resource |
| vault_jwt_auth_backend_role.this | resource |
| vault_auth_backend.gitlab | data source |
Inputs¶
| Name | Description | Type | Default | Required |
|---|---|---|---|---|
| bound_audience | JWT audience for Vault authentication. | string |
"vault" |
no |
| gitlab_instance_name | GitLab instance scope used in trust mount naming. Must match the gitlab_instance_name used in the gitlab-onboarding trust module. | string |
n/a | yes |
| gitlab_project_id | GitLab project numeric ID used as stable alias name and user claim. | string |
n/a | yes |
| gitlab_project_path | GitLab project path (group/project) used in bound_claims. | string |
n/a | yes |
| token_max_ttl | JWT login role token max TTL in seconds. | number |
86400 |
no |
| token_ttl | JWT login role token TTL in seconds. | number |
3600 |
no |
| workload_name | Short workload identifier used in entity and role naming. | string |
n/a | yes |
Outputs¶
| Name | Description |
|---|---|
| auth_role_name | JWT login role name used by GitLab pipeline login. |
| entity_id | Vault identity entity ID to be passed to use-case modules. |
| gitlab_instance_name | Echo of gitlab_instance_name input. |
| workload_name | Echo of workload_name input. |