Skip to content

terraform-vault-add-k8s-namespace-access

Workload-layer module that onboards one Kubernetes or OpenShift ServiceAccount as a Vault identity entity, alias, and JWT login role.

Layer

Workload. This module creates identity and login, but no secret policy grants.

Prerequisites

  • Trust module already provisioned (cluster-onboarding)
  • ServiceAccount namespace and name known

Inputs

Name Type Description
cluster_name string Cluster identifier, regex validated
workload_name string Workload identifier, regex validated
ocp_namespace string ServiceAccount namespace, validated (lowercase alphanumeric and hyphens, 2-63 chars)
service_account_name string ServiceAccount name, validated (lowercase alphanumeric and hyphens, 2-63 chars)
bound_audience string JWT role bound audience, default "vault"
token_ttl number JWT role TTL in seconds, default 3600, validated 1-86400
token_max_ttl number JWT role max TTL in seconds, default 86400, validated 1-86400

Outputs

Name Description
auth_role_name JWT role name used by workload login
cluster_name Echo
entity_id Entity ID for downstream use-case modules
workload_name Echo

No-code notes

  • token_policies on the workload login role is intentionally empty.
  • Policy grants are attached later through use-case identity groups.

No-code provisioning

This module is no-code enabled in the hc-ric-demo private registry (pinned to 0.3.0). Open the module, click Provision workspace, choose a project and workspace name, then complete the form.

Form fields:

Field Required Notes
cluster_name yes Cluster identifier
workload_name yes Workload identifier
ocp_namespace yes ServiceAccount namespace
service_account_name yes ServiceAccount name
bound_audience no Default "vault"

Registry usage

module "add_k8s_namespace" {
  source  = "app.terraform.io/<org>/add-k8s-namespace-access/vault"
  version = "~> 0.3.0"

  cluster_name         = "ocp-prod-eu"
  workload_name        = "payments"
  ocp_namespace        = "payments-ns"
  service_account_name = "payments-sa"
  bound_audience       = "vault"
}

Next step in chain: use-case modules consume entity_id.


Terraform reference (generated)

Generated by make generate from terraform-vault-onboarding/terraform-vault-add-k8s-namespace-access. Do not edit by hand.

Requirements

Name Version
terraform >= 1.9
vault ~> 5.10

Providers

Name Version
vault 5.10.1

Modules

No modules.

Resources

Name Type
vault_identity_entity.this resource
vault_identity_entity_alias.this resource
vault_jwt_auth_backend_role.this resource
vault_auth_backend.jwt data source

Inputs

Name Description Type Default Required
bound_audience JWT audience for Vault authentication. string "vault" no
cluster_name Cluster identifier from trust module outputs. string n/a yes
ocp_namespace OpenShift namespace (project) name. string n/a yes
service_account_name Kubernetes ServiceAccount name used for Vault authentication. string n/a yes
token_max_ttl JWT login role token max TTL in seconds. number 86400 no
token_ttl JWT login role token TTL in seconds. number 3600 no
workload_name Short workload identifier used in entity and role naming. string n/a yes

Outputs

Name Description
auth_role_name JWT login role name used by the workload for login.
cluster_name Echo of cluster_name input.
entity_id Vault identity entity ID to be passed to use-case modules.
workload_name Echo of workload_name input.