terraform-vault-add-kvv2¶
Use-case module that creates a KV-v2 mount, read-only policy, and identity group binding for one workload entity.
Layer¶
Use-case.
Prerequisites¶
- The workload module (
add-k8s-namespace-accessoradd-gitlab-project-access) must be applied first so the identity entity exists in Vault.
Inputs¶
| Name | Type | Description |
|---|---|---|
cluster_name |
string |
Cluster/scope identifier, regex validated |
integration_type |
string |
Consumption example style: kubernetes (default) or gitlab |
usecase_name |
string |
Use-case identifier, regex validated |
workload_name |
string |
Workload identifier, regex validated |
Outputs¶
| Name | Description |
|---|---|
consumption_examples |
Rendered example(s) for consuming the secret, tailored to integration_type (Kubernetes injector + VSO, or GitLab CI/CD) |
group_name |
Identity group name |
kv_mount_path |
KV-v2 mount path |
policy_name |
Read policy name |
Derived values¶
The module derives auth_role_name and jwt_auth_path internally from cluster_name, workload_name, and integration_type, matching the naming conventions used by the workload and trust modules:
auth_role_name="${cluster_name}-${workload_name}"jwt_auth_path="jwt/${cluster_name}"(kubernetes) or"jwt-gitlab/${cluster_name}"(gitlab)
Environment-specific values (VAULT_ADDRESS, VAULT_NAMESPACE) and Kubernetes deployment details (K8S_NAMESPACE, K8S_SERVICE_ACCOUNT) appear as <PLACEHOLDER> tokens in the rendered consumption_examples, to be filled in by the operator at deployment time.
No-code notes¶
- One module run grants one workload one KV-v2 use-case.
- Authorization is delivered through identity group membership; the entity is discovered automatically through
data "vault_identity_entity"using the name"${cluster_name}-${workload_name}".
No-code provisioning¶
This module is no-code enabled in the hc-ric-demo private registry (pinned to 0.5.0). Click Provision workspace on the module, pick a project and workspace name, then complete the form.
Form fields:
| Field | Required | Notes |
|---|---|---|
cluster_name |
yes | Cluster/scope identifier |
integration_type |
no | kubernetes (default) or gitlab; selects the rendered consumption example |
usecase_name |
yes | Use-case identifier |
workload_name |
yes | Workload identifier |
Registry usage¶
module "add_kvv2" {
source = "app.terraform.io/<org>/add-kvv2/vault"
version = "~> 0.5.0"
cluster_name = "ocp-prod-eu"
usecase_name = "app-config"
workload_name = "payments"
}
For a GitLab-based workload, set integration_type = "gitlab"; consumption_examples
then renders a GitLab CI/CD snippet with jwt-gitlab/ auth path.
Example rendered output¶
consumption_examples with integration_type = "kubernetes" (default) contains
both the Vault Agent Injector annotations and the Vault Secrets Operator custom
resources:
# --- Vault Agent Injector pod annotations ---
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/role: "ocp-prod-eu-payments"
vault.hashicorp.com/auth-path: "auth/jwt/ocp-prod-eu"
...
# --- Vault Secrets Operator (VSO) custom resources ---
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultStaticSecret
metadata:
name: payments-app-config
namespace: <K8S_NAMESPACE>
...
consumption_examples with integration_type = "gitlab" renders a GitLab
pipeline job:
read_vault_secret:
id_tokens:
VAULT_ID_TOKEN:
aud: vault
variables:
VAULT_ADDR: "<VAULT_ADDRESS>"
VAULT_NAMESPACE: "<VAULT_NAMESPACE>"
script:
- export VAULT_TOKEN="$(vault write -field=token auth/jwt-gitlab/ocp-prod-eu/login role=ocp-prod-eu-payments jwt=$VAULT_ID_TOKEN)"
- vault kv get kv/ocp-prod-eu/payments/app-config/app
Terraform reference (generated)¶
Generated by make generate from terraform-vault-onboarding/terraform-vault-add-kvv2. Do not edit by hand.
Requirements¶
| Name | Version |
|---|---|
| terraform | >= 1.9 |
| vault | ~> 5.10 |
Providers¶
| Name | Version |
|---|---|
| vault | 5.10.1 |
Modules¶
No modules.
Resources¶
| Name | Type |
|---|---|
| vault_identity_group.this | resource |
| vault_mount.this | resource |
| vault_policy.this | resource |
| vault_identity_entity.workload | data source |
Inputs¶
| Name | Description | Type | Default | Required |
|---|---|---|---|---|
| cluster_name | Cluster identifier used in mount, policy, and group naming. | string |
n/a | yes |
| integration_type | Workload integration style for the rendered consumption example: kubernetes (Vault Agent Injector + Vault Secrets Operator) or gitlab (GitLab CI/CD id_token login). | string |
"kubernetes" |
no |
| usecase_name | Use-case identifier used in mount, policy, and group naming. | string |
n/a | yes |
| workload_name | Workload identifier used in mount, policy, and group naming. | string |
n/a | yes |
Outputs¶
| Name | Description |
|---|---|
| consumption_examples | Rendered example(s) showing how the target workload consumes the KV secret, tailored to integration_type (Kubernetes injector + VSO, or GitLab CI/CD). |
| group_name | Identity group name granting the KV read policy. |
| kv_mount_path | KV-v2 mount path created by this use-case module. |
| policy_name | KV read policy name. |