Skip to content

terraform-vault-add-pgsql-role

Use-case module that creates a PostgreSQL static role, static-creds read policy, and identity group binding for one workload entity.

Layer

Use-case.

Prerequisites

  • Workload module must be applied first (entity is looked up by name <cluster_name>-<workload_name>)
  • Connection module outputs db_mount_path and db_connection_name

Inputs

Name Type Description
cluster_name string Cluster identifier, regex validated
db_connection_name string Database backend connection name
db_mount_path string Database backend mount path
db_username string Existing PostgreSQL username
rotation_period number Static role rotation period, default 86400
usecase_name string Use-case identifier, regex validated
workload_name string Workload identifier, regex validated

Outputs

Name Description
db_role_name Static role name
policy_name Static-creds read policy name
group_name Identity group name
injector_yaml Vault Agent Injector annotations YAML
vso_yaml Vault Secrets Operator VaultDynamicSecret YAML

No-code notes

  • One module run grants one workload one database static-creds use-case.
  • Authorization is delivered through identity group membership (entity looked up by name).
  • auth_role_name and jwt_auth_path are derived from cluster_name and workload_name.
  • Template placeholders <VAULT_ADDRESS>, <VAULT_NAMESPACE>, <K8S_NAMESPACE>, and <K8S_SERVICE_ACCOUNT> must be replaced with environment-specific values after rendering.

No-code provisioning

This module is no-code enabled in the hc-ric-demo private registry (pinned to 0.4.0). Click Provision workspace, pick a project and workspace name, then complete the form. Connection outputs come from pgsql-onboarding; the workload module must be applied first so the entity can be discovered.

Form fields:

Field Required Notes
cluster_name yes Cluster identifier
db_connection_name yes From connection module
db_mount_path yes From connection module
db_username yes Existing PostgreSQL user
usecase_name yes Use-case identifier
workload_name yes Workload identifier

Registry usage

module "add_pgsql_role" {
  source  = "app.terraform.io/<org>/add-pgsql-role/vault"
  version = "~> 0.4.0"

  cluster_name       = "ocp-prod-eu"
  workload_name      = "payments"
  usecase_name       = "orders-db"
  db_mount_path      = "db/ocp-prod-eu/payments-db"
  db_connection_name = "payments-db"
  db_username        = "payments_app"
}

Example rendered YAML

injector_yaml example:

vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/role: "ocp-prod-eu-payments"
vault.hashicorp.com/auth-path: "auth/jwt/ocp-prod-eu"
vault.hashicorp.com/service: "<VAULT_ADDRESS>"
vault.hashicorp.com/namespace: "<VAULT_NAMESPACE>"
vault.hashicorp.com/agent-inject-secret-db.json: "db/ocp-prod-eu/payments-db/static-creds/ocp-prod-eu-payments-orders-db-pg"

vso_yaml example:

apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultDynamicSecret
metadata:
  name: payments-orders-db
  namespace: <K8S_NAMESPACE>
spec:
  vaultAuthRef: ocp-prod-eu-payments
  mount: db/ocp-prod-eu/payments-db
  path: static-creds/ocp-prod-eu-payments-orders-db-pg
  destination:
    create: true
    name: payments-orders-db
  refreshAfter: 30s

Terraform reference (generated)

Generated by make generate from terraform-vault-onboarding/terraform-vault-add-pgsql-role. Do not edit by hand.

Requirements

Name Version
terraform >= 1.9
vault ~> 5.10

Providers

Name Version
vault 5.10.1

Modules

No modules.

Resources

Name Type
vault_database_secret_backend_static_role.this resource
vault_identity_group.this resource
vault_policy.this resource
vault_identity_entity.workload data source

Inputs

Name Description Type Default Required
cluster_name Cluster identifier used in role, policy, and group naming. string n/a yes
db_connection_name Database backend connection name from onboard-pgsql-connection output. string n/a yes
db_mount_path Database backend mount path from onboard-pgsql-connection output. string n/a yes
db_username Existing PostgreSQL username managed by Vault static role. string n/a yes
rotation_period Static role password rotation period in seconds. number 86400 no
usecase_name Use-case identifier used in role, policy, and group naming. string n/a yes
workload_name Workload identifier used in role, policy, and group naming. string n/a yes

Outputs

Name Description
db_role_name Database static role name created by this module.
group_name Identity group name granting database static credential read policy.
injector_yaml Rendered Vault Agent Injector annotations snippet for static-creds path.
policy_name Database static credential read policy name.
vso_yaml Rendered Vault Secrets Operator VaultAuth and VaultDynamicSecret snippet for static-creds path.