Workload-layer module that onboards one Kubernetes or OpenShift ServiceAccount as a Vault identity entity, alias, and JWT login role.
Layer
Workload. This module creates identity and login, but no secret policy grants.
Prerequisites
- Trust module already provisioned (cluster-onboarding)
- ServiceAccount namespace and name known
| Name |
Type |
Description |
cluster_name |
string |
Cluster identifier, regex validated |
workload_name |
string |
Workload identifier, regex validated |
ocp_namespace |
string |
ServiceAccount namespace, validated (lowercase alphanumeric and hyphens, 2-63 chars) |
service_account_name |
string |
ServiceAccount name, validated (lowercase alphanumeric and hyphens, 2-63 chars) |
bound_audience |
string |
JWT role bound audience, default "vault" |
token_ttl |
number |
JWT role TTL in seconds, default 3600, validated 1-86400 |
token_max_ttl |
number |
JWT role max TTL in seconds, default 86400, validated 1-86400 |
Outputs
| Name |
Description |
auth_role_name |
JWT role name used by workload login |
cluster_name |
Echo |
entity_id |
Entity ID for downstream use-case modules |
workload_name |
Echo |
No-code notes
token_policies on the workload login role is intentionally empty.
- Policy grants are attached later through use-case identity groups.
No-code provisioning
This module is no-code enabled in the hc-ric-demo private registry (pinned to 0.3.0). Open the module, click Provision workspace, choose a project and workspace name, then complete the form.
Form fields:
| Field |
Required |
Notes |
cluster_name |
yes |
Cluster identifier |
workload_name |
yes |
Workload identifier |
ocp_namespace |
yes |
ServiceAccount namespace |
service_account_name |
yes |
ServiceAccount name |
bound_audience |
no |
Default "vault" |
Registry usage
module "add_k8s_namespace" {
source = "app.terraform.io/<org>/add-k8s-namespace-access/vault"
version = "~> 0.3.0"
cluster_name = "ocp-prod-eu"
workload_name = "payments"
ocp_namespace = "payments-ns"
service_account_name = "payments-sa"
bound_audience = "vault"
}
Next step in chain: use-case modules consume entity_id.
Generated by make generate from terraform-vault-onboarding/terraform-vault-add-k8s-namespace-access. Do not edit by hand.
Requirements
Providers
| Name |
Version |
| vault |
5.10.1 |
Modules
No modules.
Resources
| Name |
Description |
Type |
Default |
Required |
| bound_audience |
JWT audience for Vault authentication. |
string |
"vault" |
no |
| cluster_name |
Cluster identifier from trust module outputs. |
string |
n/a |
yes |
| ocp_namespace |
OpenShift namespace (project) name. |
string |
n/a |
yes |
| service_account_name |
Kubernetes ServiceAccount name used for Vault authentication. |
string |
n/a |
yes |
| token_max_ttl |
JWT login role token max TTL in seconds. |
number |
86400 |
no |
| token_ttl |
JWT login role token TTL in seconds. |
number |
3600 |
no |
| workload_name |
Short workload identifier used in entity and role naming. |
string |
n/a |
yes |
Outputs