Skip to content

terraform-vault-cluster-onboarding

Trust-layer module that creates one Vault JWT auth backend at jwt/<cluster_name> for an OpenShift or Kubernetes issuer.

Layer

Trust. This module creates trust only. It does not create workloads, policies, or secret engines.

Prerequisites

  • HCP Terraform project configured with Vault dynamic credentials (TFC_VAULT_*)
  • Tenant namespace inherited through VAULT_NAMESPACE

No-code notes

  • This module is no-code ready and declares its own vault provider.
  • It creates trust only and outputs values for workload modules.
  • It does not set resource-level namespace.

Inputs

Name Type Description
cluster_name string Cluster identifier, regex validated
jwt_issuer string OIDC issuer URL
oidc_discovery_url string Optional discovery URL, mutually exclusive
jwks_url string Optional JWKS URL, mutually exclusive
jwt_validation_pubkey string Optional single PEM public key, mutually exclusive
default_lease_ttl string Tune default TTL, default 1h
max_lease_ttl string Tune max TTL, default 24h

Outputs

Name Description
jwt_auth_path JWT mount path (jwt/<cluster_name>)
jwt_mount_accessor JWT mount accessor for entity alias creation
cluster_name Echo

No-code provisioning

This module is no-code enabled in the hc-ric-demo private registry (pinned to 0.2.0). To deploy without writing HCL: open the module in the registry, click Provision workspace, choose a project and workspace name, then complete the form.

Form fields:

Field Required Notes
cluster_name yes Cluster identifier
jwt_issuer yes OIDC issuer URL
oidc_discovery_url / jwks_url / jwt_validation_pubkey yes Set exactly one
default_lease_ttl / max_lease_ttl no Tune TTLs

The first run plans automatically after the workspace is created.

Registry usage

module "cluster_onboarding" {
  source  = "app.terraform.io/<org>/cluster-onboarding/vault"
  version = "~> 0.2.0"

  cluster_name       = "ocp-prod-eu"
  jwt_issuer         = "https://kubernetes.default.svc"
  oidc_discovery_url = "https://kubernetes.default.svc"
}

Next step in chain: terraform-vault-add-k8s-namespace-access.


Terraform reference (generated)

Generated by make generate from terraform-vault-onboarding/terraform-vault-cluster-onboarding. Do not edit by hand.

Requirements

Name Version
terraform >= 1.9
vault ~> 5.10

Providers

Name Version
vault 5.10.1

Modules

No modules.

Resources

Name Type
vault_jwt_auth_backend.this resource

Inputs

Name Description Type Default Required
cluster_name Short cluster identifier used in mount naming. string n/a yes
default_lease_ttl Default lease TTL for the JWT auth backend tune block. string "1h" no
jwks_url Optional JWKS URL for JWT signature verification. string "" no
jwt_issuer OIDC issuer URL used as bound_issuer for the JWT auth backend. string n/a yes
jwt_validation_pubkey Single PEM public key for JWT validation. Leave empty to use OIDC discovery or JWKS URL instead. string "" no
max_lease_ttl Maximum lease TTL for the JWT auth backend tune block. string "24h" no
oidc_discovery_url Optional OIDC discovery URL for JWT auth backend config. string "" no

Outputs

Name Description
cluster_name Echo of cluster_name input.
jwt_auth_path JWT auth backend path for this cluster trust mount.
jwt_mount_accessor JWT auth mount accessor for identity alias creation in workload modules.