Skip to content

terraform-vault-pgsql-onboarding

Use-case root-configuration module that mounts the database secrets engine and creates one PostgreSQL connection.

Layer

Use-case root configuration.

Prerequisites

  • HCP Terraform project configured with Vault dynamic credentials
  • PostgreSQL reachable from Vault

Inputs

Name Type Description
cluster_name string Cluster identifier, regex validated
db_name string Database identifier, regex validated
pg_connection_url string Connection URL with placeholders
pg_username string Root username, sensitive
pg_password string Root password, sensitive
allowed_roles string Optional allowed role glob
rotate_root bool Add root rotation statement, default false

Outputs

Name Description
db_mount_path Database mount path
db_connection_name Connection name
cluster_name Echo

No-code notes

  • This module is the shared database root configuration layer.
  • It creates no workload, policy grant, identity group, or YAML snippets.

No-code provisioning

This module is no-code enabled in the hc-ric-demo private registry (pinned to 0.2.0). Click Provision workspace, pick a project and workspace name, then complete the form. pg_username and pg_password are sensitive.

Form fields:

Field Required Notes
cluster_name yes Cluster identifier
db_name yes Database identifier
pg_connection_url yes URL with {{username}}/{{password}}
pg_username yes Root username (sensitive)
pg_password yes Root password (sensitive)
allowed_roles no Glob pattern for allowed role names (defaults to <cluster_name>-* when empty)
rotate_root no Default false

Registry usage

module "onboard_pgsql_connection" {
  source  = "app.terraform.io/<org>/onboard-pgsql-connection/vault"
  version = "~> 0.2.0"

  cluster_name      = "ocp-prod-eu"
  db_name           = "payments-db"
  pg_connection_url = "postgresql://{{username}}:{{password}}@db.example.com:5432/payments?sslmode=require"
  pg_username       = var.pg_username
  pg_password       = var.pg_password
}

Next step in chain: terraform-vault-add-pgsql-role.


Terraform reference (generated)

Generated by make generate from terraform-vault-onboarding/terraform-vault-pgsql-onboarding. Do not edit by hand.

Requirements

Name Version
terraform >= 1.9
vault ~> 5.10

Providers

Name Version
vault 5.10.1

Modules

No modules.

Resources

Name Type
vault_database_secret_backend_connection.this resource
vault_mount.this resource

Inputs

Name Description Type Default Required
allowed_roles Role name glob allowed to register against this DB connection. Empty defaults to -*. string "" no
cluster_name Cluster identifier used in DB mount naming. string n/a yes
db_name Database logical identifier used in mount and connection naming. string n/a yes
pg_connection_url PostgreSQL connection URL with {{username}} and {{password}} placeholders. string n/a yes
pg_password PostgreSQL root password used by the database secrets engine connection. string n/a yes
pg_username PostgreSQL root username used by the database secrets engine connection. string n/a yes
rotate_root Whether to set root rotation statements on the connection. bool false no

Outputs

Name Description
cluster_name Echo of cluster_name input.
db_connection_name Database backend connection name used by downstream role module.
db_mount_path Database backend mount path used by downstream role module.