Use-case root-configuration module that mounts the database secrets engine and creates one PostgreSQL connection.
Layer
Use-case root configuration.
Prerequisites
- HCP Terraform project configured with Vault dynamic credentials
- PostgreSQL reachable from Vault
| Name |
Type |
Description |
cluster_name |
string |
Cluster identifier, regex validated |
db_name |
string |
Database identifier, regex validated |
pg_connection_url |
string |
Connection URL with placeholders |
pg_username |
string |
Root username, sensitive |
pg_password |
string |
Root password, sensitive |
allowed_roles |
string |
Optional allowed role glob |
rotate_root |
bool |
Add root rotation statement, default false |
Outputs
| Name |
Description |
db_mount_path |
Database mount path |
db_connection_name |
Connection name |
cluster_name |
Echo |
No-code notes
- This module is the shared database root configuration layer.
- It creates no workload, policy grant, identity group, or YAML snippets.
No-code provisioning
This module is no-code enabled in the hc-ric-demo private registry (pinned to 0.2.0). Click Provision workspace, pick a project and workspace name, then complete the form. pg_username and pg_password are sensitive.
Form fields:
| Field |
Required |
Notes |
cluster_name |
yes |
Cluster identifier |
db_name |
yes |
Database identifier |
pg_connection_url |
yes |
URL with {{username}}/{{password}} |
pg_username |
yes |
Root username (sensitive) |
pg_password |
yes |
Root password (sensitive) |
allowed_roles |
no |
Glob pattern for allowed role names (defaults to <cluster_name>-* when empty) |
rotate_root |
no |
Default false |
Registry usage
module "onboard_pgsql_connection" {
source = "app.terraform.io/<org>/onboard-pgsql-connection/vault"
version = "~> 0.2.0"
cluster_name = "ocp-prod-eu"
db_name = "payments-db"
pg_connection_url = "postgresql://{{username}}:{{password}}@db.example.com:5432/payments?sslmode=require"
pg_username = var.pg_username
pg_password = var.pg_password
}
Next step in chain: terraform-vault-add-pgsql-role.
Generated by make generate from terraform-vault-onboarding/terraform-vault-pgsql-onboarding. Do not edit by hand.
Requirements
Providers
| Name |
Version |
| vault |
5.10.1 |
Modules
No modules.
Resources
| Name |
Description |
Type |
Default |
Required |
| allowed_roles |
Role name glob allowed to register against this DB connection. Empty defaults to -*. |
string |
"" |
no |
| cluster_name |
Cluster identifier used in DB mount naming. |
string |
n/a |
yes |
| db_name |
Database logical identifier used in mount and connection naming. |
string |
n/a |
yes |
| pg_connection_url |
PostgreSQL connection URL with {{username}} and {{password}} placeholders. |
string |
n/a |
yes |
| pg_password |
PostgreSQL root password used by the database secrets engine connection. |
string |
n/a |
yes |
| pg_username |
PostgreSQL root username used by the database secrets engine connection. |
string |
n/a |
yes |
| rotate_root |
Whether to set root rotation statements on the connection. |
bool |
false |
no |
Outputs
| Name |
Description |
| cluster_name |
Echo of cluster_name input. |
| db_connection_name |
Database backend connection name used by downstream role module. |
| db_mount_path |
Database backend mount path used by downstream role module. |