terraform-vault-gitlab-onboarding¶
Trust-layer module that creates one Vault JWT auth backend at jwt-gitlab/<gitlab_instance_name> for GitLab.
Layer¶
Trust. This module creates trust only. It does not create workloads, policies, or secret engines.
Prerequisites¶
- HCP Terraform project configured with Vault dynamic credentials (
TFC_VAULT_*) - Tenant namespace inherited through
VAULT_NAMESPACE
No-code notes¶
- This module is no-code ready and declares its own
vaultprovider. - It creates trust only and outputs values for workload modules.
- It uses a separate mount path from OCP trust (
jwt-gitlab/<gitlab_instance_name>).
Inputs¶
| Name | Type | Description |
|---|---|---|
gitlab_instance_name |
string |
One of cloud, dedicated-prod, dedicated-dev |
oidc_discovery_url |
string |
Discovery URL, mutually exclusive; accepts base or .well-known form, normalised automatically |
jwt_issuer |
string |
Optional bound_issuer; derived from oidc_discovery_url when empty |
jwks_url |
string |
Optional JWKS URL, mutually exclusive |
jwt_validation_pubkey |
string |
Single PEM public key for JWT validation; leave empty to use OIDC discovery or JWKS URL |
default_lease_ttl |
string |
Tune default TTL, default 1h |
max_lease_ttl |
string |
Tune max TTL, default 24h |
Outputs¶
| Name | Description |
|---|---|
jwt_auth_path |
JWT mount path (jwt-gitlab/<gitlab_instance_name>) |
jwt_mount_accessor |
JWT mount accessor for entity alias creation |
gitlab_instance_name |
Echo |
No-code provisioning¶
This module is no-code enabled in the hc-ric-demo private registry (pinned to 0.3.0). Click Provision workspace, pick a project and workspace name, then complete the form. gitlab_instance_name is presented as a dropdown limited to cloud, dedicated-prod, dedicated-dev.
No-code UX note: The
gitlab_instance_namedropdown is driven by explicit no-codevariable-optionsconfigured on the module in the registry, not by the module’scontains()validation (which only validates on submit). These options (cloud,dedicated-prod,dedicated-dev) are a registry-side setting applied using thetfe_no_code_moduleresource or the no-code modules API. They are not stored in this repository, so re-enabling no-code provisioning for the module requires re-applying them.
Form fields:
| Field | Required | Notes |
|---|---|---|
gitlab_instance_name |
yes | Dropdown: cloud / dedicated-prod / dedicated-dev |
oidc_discovery_url / jwks_url / jwt_validation_pubkey |
yes | Set exactly one; discovery URL accepts base or .well-known form |
jwt_issuer |
no | Derived from oidc_discovery_url when empty |
Registry usage¶
module "gitlab_onboarding" {
source = "app.terraform.io/<org>/gitlab-onboarding/vault"
version = "~> 0.3.0"
gitlab_instance_name = "cloud"
oidc_discovery_url = "https://gitlab.com"
}
Next step in chain: terraform-vault-add-gitlab-project-access.
Terraform reference (generated)¶
Generated by make generate from terraform-vault-onboarding/terraform-vault-gitlab-onboarding. Do not edit by hand.
Requirements¶
| Name | Version |
|---|---|
| terraform | >= 1.9 |
| vault | ~> 5.10 |
Providers¶
| Name | Version |
|---|---|
| vault | 5.10.1 |
Modules¶
No modules.
Resources¶
| Name | Type |
|---|---|
| vault_jwt_auth_backend.this | resource |
Inputs¶
| Name | Description | Type | Default | Required |
|---|---|---|---|---|
| default_lease_ttl | Default lease TTL for the JWT auth backend tune block. | string |
"1h" |
no |
| gitlab_instance_name | GitLab instance scope used in trust mount naming. | string |
n/a | yes |
| jwks_url | Optional JWKS URL for JWT signature verification. | string |
"" |
no |
| jwt_issuer | Optional GitLab OIDC issuer (bound_issuer). Derived from oidc_discovery_url when empty. | string |
"" |
no |
| jwt_validation_pubkey | Single PEM public key for JWT validation. Leave empty to use OIDC discovery or JWKS URL instead. | string |
"" |
no |
| max_lease_ttl | Maximum lease TTL for the JWT auth backend tune block. | string |
"24h" |
no |
| oidc_discovery_url | OIDC discovery URL for JWT auth backend config. Set exactly one of oidc_discovery_url, jwks_url, or jwt_validation_pubkey. | string |
"" |
no |
Outputs¶
| Name | Description |
|---|---|
| gitlab_instance_name | Echo of gitlab_instance_name input. |
| jwt_auth_path | JWT auth backend path for this GitLab trust mount. |
| jwt_mount_accessor | JWT auth mount accessor for identity alias creation in workload modules. |