Skip to content

terraform-vault-add-kvv2

Use-case module that creates a KV-v2 mount, read-only policy, and identity group binding for one workload entity.

Layer

Use-case.

Prerequisites

  • The workload module (add-k8s-namespace-access or add-gitlab-project-access) must be applied first so the identity entity exists in Vault.

Inputs

Name Type Description
cluster_name string Cluster/scope identifier, regex validated
integration_type string Consumption example style: kubernetes (default) or gitlab
usecase_name string Use-case identifier, regex validated
workload_name string Workload identifier, regex validated

Outputs

Name Description
consumption_examples Rendered example(s) for consuming the secret, tailored to integration_type (Kubernetes injector + VSO, or GitLab CI/CD)
group_name Identity group name
kv_mount_path KV-v2 mount path
policy_name Read policy name

Derived values

The module derives auth_role_name and jwt_auth_path internally from cluster_name, workload_name, and integration_type, matching the naming conventions used by the workload and trust modules:

  • auth_role_name = "${cluster_name}-${workload_name}"
  • jwt_auth_path = "jwt/${cluster_name}" (kubernetes) or "jwt-gitlab/${cluster_name}" (gitlab)

Environment-specific values (VAULT_ADDRESS, VAULT_NAMESPACE) and Kubernetes deployment details (K8S_NAMESPACE, K8S_SERVICE_ACCOUNT) appear as <PLACEHOLDER> tokens in the rendered consumption_examples, to be filled in by the operator at deployment time.

No-code notes

  • One module run grants one workload one KV-v2 use-case.
  • Authorization is delivered through identity group membership; the entity is discovered automatically through data "vault_identity_entity" using the name "${cluster_name}-${workload_name}".

No-code provisioning

This module is no-code enabled in the hc-ric-demo private registry (pinned to 0.5.0). Click Provision workspace on the module, pick a project and workspace name, then complete the form.

Form fields:

Field Required Notes
cluster_name yes Cluster/scope identifier
integration_type no kubernetes (default) or gitlab; selects the rendered consumption example
usecase_name yes Use-case identifier
workload_name yes Workload identifier

Registry usage

module "add_kvv2" {
  source  = "app.terraform.io/<org>/add-kvv2/vault"
  version = "~> 0.5.0"

  cluster_name  = "ocp-prod-eu"
  usecase_name  = "app-config"
  workload_name = "payments"
}

For a GitLab-based workload, set integration_type = "gitlab"; consumption_examples then renders a GitLab CI/CD snippet with jwt-gitlab/ auth path.

Example rendered output

consumption_examples with integration_type = "kubernetes" (default) contains both the Vault Agent Injector annotations and the Vault Secrets Operator custom resources:

# --- Vault Agent Injector pod annotations ---
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/role: "ocp-prod-eu-payments"
vault.hashicorp.com/auth-path: "auth/jwt/ocp-prod-eu"
...

# --- Vault Secrets Operator (VSO) custom resources ---
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultStaticSecret
metadata:
  name: payments-app-config
  namespace: <K8S_NAMESPACE>
...

consumption_examples with integration_type = "gitlab" renders a GitLab pipeline job:

read_vault_secret:
  id_tokens:
    VAULT_ID_TOKEN:
      aud: vault
  variables:
    VAULT_ADDR: "<VAULT_ADDRESS>"
    VAULT_NAMESPACE: "<VAULT_NAMESPACE>"
  script:
    - export VAULT_TOKEN="$(vault write -field=token auth/jwt-gitlab/ocp-prod-eu/login role=ocp-prod-eu-payments jwt=$VAULT_ID_TOKEN)"
    - vault kv get kv/ocp-prod-eu/payments/app-config/app

Terraform reference (generated)

Generated by make generate from terraform-vault-onboarding/terraform-vault-add-kvv2. Do not edit by hand.

Requirements

Name Version
terraform >= 1.9
vault ~> 5.10

Providers

Name Version
vault 5.10.1

Modules

No modules.

Resources

Name Type
vault_identity_group.this resource
vault_mount.this resource
vault_policy.this resource
vault_identity_entity.workload data source

Inputs

Name Description Type Default Required
cluster_name Cluster identifier used in mount, policy, and group naming. string n/a yes
integration_type Workload integration style for the rendered consumption example: kubernetes (Vault Agent Injector + Vault Secrets Operator) or gitlab (GitLab CI/CD id_token login). string "kubernetes" no
usecase_name Use-case identifier used in mount, policy, and group naming. string n/a yes
workload_name Workload identifier used in mount, policy, and group naming. string n/a yes

Outputs

Name Description
consumption_examples Rendered example(s) showing how the target workload consumes the KV secret, tailored to integration_type (Kubernetes injector + VSO, or GitLab CI/CD).
group_name Identity group name granting the KV read policy.
kv_mount_path KV-v2 mount path created by this use-case module.
policy_name KV read policy name.