terraform-vault-add-pgsql-role¶
Use-case module that creates a PostgreSQL static role, static-creds read policy, and identity group binding for one workload entity.
Layer¶
Use-case.
Prerequisites¶
- Workload module must be applied first (entity is looked up by name
<cluster_name>-<workload_name>) - Connection module outputs
db_mount_pathanddb_connection_name
Inputs¶
| Name | Type | Description |
|---|---|---|
cluster_name |
string |
Cluster identifier, regex validated |
db_connection_name |
string |
Database backend connection name |
db_mount_path |
string |
Database backend mount path |
db_username |
string |
Existing PostgreSQL username |
rotation_period |
number |
Static role rotation period, default 86400 |
usecase_name |
string |
Use-case identifier, regex validated |
workload_name |
string |
Workload identifier, regex validated |
Outputs¶
| Name | Description |
|---|---|
db_role_name |
Static role name |
policy_name |
Static-creds read policy name |
group_name |
Identity group name |
injector_yaml |
Vault Agent Injector annotations YAML |
vso_yaml |
Vault Secrets Operator VaultDynamicSecret YAML |
No-code notes¶
- One module run grants one workload one database static-creds use-case.
- Authorization is delivered through identity group membership (entity looked up by name).
auth_role_nameandjwt_auth_pathare derived fromcluster_nameandworkload_name.- Template placeholders
<VAULT_ADDRESS>,<VAULT_NAMESPACE>,<K8S_NAMESPACE>, and<K8S_SERVICE_ACCOUNT>must be replaced with environment-specific values after rendering.
No-code provisioning¶
This module is no-code enabled in the hc-ric-demo private registry (pinned to 0.4.0). Click Provision workspace, pick a project and workspace name, then complete the form. Connection outputs come from pgsql-onboarding; the workload module must be applied first so the entity can be discovered.
Form fields:
| Field | Required | Notes |
|---|---|---|
cluster_name |
yes | Cluster identifier |
db_connection_name |
yes | From connection module |
db_mount_path |
yes | From connection module |
db_username |
yes | Existing PostgreSQL user |
usecase_name |
yes | Use-case identifier |
workload_name |
yes | Workload identifier |
Registry usage¶
module "add_pgsql_role" {
source = "app.terraform.io/<org>/add-pgsql-role/vault"
version = "~> 0.4.0"
cluster_name = "ocp-prod-eu"
workload_name = "payments"
usecase_name = "orders-db"
db_mount_path = "db/ocp-prod-eu/payments-db"
db_connection_name = "payments-db"
db_username = "payments_app"
}
Example rendered YAML¶
injector_yaml example:
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/role: "ocp-prod-eu-payments"
vault.hashicorp.com/auth-path: "auth/jwt/ocp-prod-eu"
vault.hashicorp.com/service: "<VAULT_ADDRESS>"
vault.hashicorp.com/namespace: "<VAULT_NAMESPACE>"
vault.hashicorp.com/agent-inject-secret-db.json: "db/ocp-prod-eu/payments-db/static-creds/ocp-prod-eu-payments-orders-db-pg"
vso_yaml example:
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultDynamicSecret
metadata:
name: payments-orders-db
namespace: <K8S_NAMESPACE>
spec:
vaultAuthRef: ocp-prod-eu-payments
mount: db/ocp-prod-eu/payments-db
path: static-creds/ocp-prod-eu-payments-orders-db-pg
destination:
create: true
name: payments-orders-db
refreshAfter: 30s
Terraform reference (generated)¶
Generated by make generate from terraform-vault-onboarding/terraform-vault-add-pgsql-role. Do not edit by hand.
Requirements¶
| Name | Version |
|---|---|
| terraform | >= 1.9 |
| vault | ~> 5.10 |
Providers¶
| Name | Version |
|---|---|
| vault | 5.10.1 |
Modules¶
No modules.
Resources¶
| Name | Type |
|---|---|
| vault_database_secret_backend_static_role.this | resource |
| vault_identity_group.this | resource |
| vault_policy.this | resource |
| vault_identity_entity.workload | data source |
Inputs¶
| Name | Description | Type | Default | Required |
|---|---|---|---|---|
| cluster_name | Cluster identifier used in role, policy, and group naming. | string |
n/a | yes |
| db_connection_name | Database backend connection name from onboard-pgsql-connection output. | string |
n/a | yes |
| db_mount_path | Database backend mount path from onboard-pgsql-connection output. | string |
n/a | yes |
| db_username | Existing PostgreSQL username managed by Vault static role. | string |
n/a | yes |
| rotation_period | Static role password rotation period in seconds. | number |
86400 |
no |
| usecase_name | Use-case identifier used in role, policy, and group naming. | string |
n/a | yes |
| workload_name | Workload identifier used in role, policy, and group naming. | string |
n/a | yes |
Outputs¶
| Name | Description |
|---|---|
| db_role_name | Database static role name created by this module. |
| group_name | Identity group name granting database static credential read policy. |
| injector_yaml | Rendered Vault Agent Injector annotations snippet for static-creds path. |
| policy_name | Database static credential read policy name. |
| vso_yaml | Rendered Vault Secrets Operator VaultAuth and VaultDynamicSecret snippet for static-creds path. |