Repository navigation
Terraform: the idm-environment module, examples and docs; secret-manager helper commands - #33
Merged
Merged
Conversation
… helper commands A module that writes an environment's files (0600) and runs vault.deploy for a tree from terraform apply, with credentials as literals or as commands the CLI runs at deploy time; a lab and an AWS Secrets Manager example; docs/terraform.md. bin/secrets/ holds the CyberArk CCP and BeyondTrust Password Safe commands a <key>Command= reference can call. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Per Jerry: the Terraform module (the first of the follow-ups from the secret-manager work), and the helper commands move here so the secret-manager integration is complete without the web app — it always was the CLI's
<key>Command=form; the page only writes the line.What it adds
terraform/modules/idm-environment: one environment per instance. Writesenvironments-<name>.propertiesandsecrets-<name>.properties(local_sensitive_file,0600) from its inputs — URL, bind DN, driver set, tier, trust, SSH,requires, extra properties; the bind password and driver secrets as literals (bind_password,secrets) or as commands the CLI runs at deploy time (bind_password_command,secret_commands). Withdeploy_mode = "deploy"aterraform_data+local-execrunsidm vault.deploy <tree> --env <name> --json --yes --confirm <name> --secrets missing(--driver,--no-restart,--allow-missing-secretsexposed;--delete-driverdeliberately not), withIDM_ENVIRONMENTSpointing at its own file; it reruns when anything under the tree or in either file changes, and is a no-op otherwise.dry-runplans only,nonewrites the files only. Outputs the file paths and the exact command.terraform/examples/lab(literal password, dry run) andterraform/examples/aws(Terraform provisions the shim password into AWS Secrets Manager; the environment references it by name, so nothing is copied into files or state).docs/terraform.md: the two patterns (secrets by name; the module), what stays with the CLI, and that a native provider is not built. README and docs index link it.bin/secrets/cyberark-ccp.shandbin/secrets/beyondtrust.sh: the two managers whose API takes several steps, as commands a<key>Command=line can call (curl/python3only; their own keys fromCCP_CERT,BT_API_KEY,BT_RUNAS)..gitignore: Terraform working files.Verified
terraform validateandfmt -checkon the module and both examples. The lab example run from a scratch copy against edir3:applywrote both files (0600, password not in the listing), dry-ran the unchanged tree ("ok":true), then withdeploy_mode = "deploy"ran the realvault.deploy(nothing to deploy, verified), and a secondapplyreported no changes. The scratch state, which held the lab password as a literal, was deleted.🤖 Generated with Claude Code