Skip to content

terraform-vault-gitlab-onboarding

Trust-layer module that creates one Vault JWT auth backend at jwt-gitlab/<gitlab_instance_name> for GitLab.

Layer

Trust. This module creates trust only. It does not create workloads, policies, or secret engines.

Prerequisites

  • HCP Terraform project configured with Vault dynamic credentials (TFC_VAULT_*)
  • Tenant namespace inherited through VAULT_NAMESPACE

No-code notes

  • This module is no-code ready and declares its own vault provider.
  • It creates trust only and outputs values for workload modules.
  • It uses a separate mount path from OCP trust (jwt-gitlab/<gitlab_instance_name>).

Inputs

Name Type Description
gitlab_instance_name string One of cloud, dedicated-prod, dedicated-dev
oidc_discovery_url string Discovery URL, mutually exclusive; accepts base or .well-known form, normalised automatically
jwt_issuer string Optional bound_issuer; derived from oidc_discovery_url when empty
jwks_url string Optional JWKS URL, mutually exclusive
jwt_validation_pubkey string Single PEM public key for JWT validation; leave empty to use OIDC discovery or JWKS URL
default_lease_ttl string Tune default TTL, default 1h
max_lease_ttl string Tune max TTL, default 24h

Outputs

Name Description
jwt_auth_path JWT mount path (jwt-gitlab/<gitlab_instance_name>)
jwt_mount_accessor JWT mount accessor for entity alias creation
gitlab_instance_name Echo

No-code provisioning

This module is no-code enabled in the hc-ric-demo private registry (pinned to 0.3.0). Click Provision workspace, pick a project and workspace name, then complete the form. gitlab_instance_name is presented as a dropdown limited to cloud, dedicated-prod, dedicated-dev.

No-code UX note: The gitlab_instance_name dropdown is driven by explicit no-code variable-options configured on the module in the registry, not by the module’s contains() validation (which only validates on submit). These options (cloud, dedicated-prod, dedicated-dev) are a registry-side setting applied using the tfe_no_code_module resource or the no-code modules API. They are not stored in this repository, so re-enabling no-code provisioning for the module requires re-applying them.

Form fields:

Field Required Notes
gitlab_instance_name yes Dropdown: cloud / dedicated-prod / dedicated-dev
oidc_discovery_url / jwks_url / jwt_validation_pubkey yes Set exactly one; discovery URL accepts base or .well-known form
jwt_issuer no Derived from oidc_discovery_url when empty

Registry usage

module "gitlab_onboarding" {
  source  = "app.terraform.io/<org>/gitlab-onboarding/vault"
  version = "~> 0.3.0"

  gitlab_instance_name = "cloud"
  oidc_discovery_url = "https://gitlab.com"
}

Next step in chain: terraform-vault-add-gitlab-project-access.


Terraform reference (generated)

Generated by make generate from terraform-vault-onboarding/terraform-vault-gitlab-onboarding. Do not edit by hand.

Requirements

Name Version
terraform >= 1.9
vault ~> 5.10

Providers

Name Version
vault 5.10.1

Modules

No modules.

Resources

Name Type
vault_jwt_auth_backend.this resource

Inputs

Name Description Type Default Required
default_lease_ttl Default lease TTL for the JWT auth backend tune block. string "1h" no
gitlab_instance_name GitLab instance scope used in trust mount naming. string n/a yes
jwks_url Optional JWKS URL for JWT signature verification. string "" no
jwt_issuer Optional GitLab OIDC issuer (bound_issuer). Derived from oidc_discovery_url when empty. string "" no
jwt_validation_pubkey Single PEM public key for JWT validation. Leave empty to use OIDC discovery or JWKS URL instead. string "" no
max_lease_ttl Maximum lease TTL for the JWT auth backend tune block. string "24h" no
oidc_discovery_url OIDC discovery URL for JWT auth backend config. Set exactly one of oidc_discovery_url, jwks_url, or jwt_validation_pubkey. string "" no

Outputs

Name Description
gitlab_instance_name Echo of gitlab_instance_name input.
jwt_auth_path JWT auth backend path for this GitLab trust mount.
jwt_mount_accessor JWT auth mount accessor for identity alias creation in workload modules.