Skip to content

Terraform: the idm-environment module, examples and docs; secret-manager helper commands - #33

Merged
jcombs-pointblue merged 1 commit into
masterfrom
claude/terraform-module
Oct 6, 2026
Merged

jcombs-pointblue merged 1 commit into
masterfrom
claude/terraform-module

Conversation

@jcombs-pointblue

Copy link
Copy Markdown
Contributor

Per Jerry: the Terraform module (the first of the follow-ups from the secret-manager work), and the helper commands move here so the secret-manager integration is complete without the web app — it always was the CLI's <key>Command= form; the page only writes the line.

What it adds

  • terraform/modules/idm-environment: one environment per instance. Writes environments-<name>.properties and secrets-<name>.properties (local_sensitive_file, 0600) from its inputs — URL, bind DN, driver set, tier, trust, SSH, requires, extra properties; the bind password and driver secrets as literals (bind_password, secrets) or as commands the CLI runs at deploy time (bind_password_command, secret_commands). With deploy_mode = "deploy" a terraform_data + local-exec runs idm vault.deploy <tree> --env <name> --json --yes --confirm <name> --secrets missing (--driver, --no-restart, --allow-missing-secrets exposed; --delete-driver deliberately not), with IDM_ENVIRONMENTS pointing at its own file; it reruns when anything under the tree or in either file changes, and is a no-op otherwise. dry-run plans only, none writes the files only. Outputs the file paths and the exact command.
  • Examples: terraform/examples/lab (literal password, dry run) and terraform/examples/aws (Terraform provisions the shim password into AWS Secrets Manager; the environment references it by name, so nothing is copied into files or state).
  • docs/terraform.md: the two patterns (secrets by name; the module), what stays with the CLI, and that a native provider is not built. README and docs index link it.
  • bin/secrets/cyberark-ccp.sh and bin/secrets/beyondtrust.sh: the two managers whose API takes several steps, as commands a <key>Command= line can call (curl/python3 only; their own keys from CCP_CERT, BT_API_KEY, BT_RUNAS).
  • .gitignore: Terraform working files.

Verified

terraform validate and fmt -check on the module and both examples. The lab example run from a scratch copy against edir3: apply wrote both files (0600, password not in the listing), dry-ran the unchanged tree ("ok":true), then with deploy_mode = "deploy" ran the real vault.deploy (nothing to deploy, verified), and a second apply reported no changes. The scratch state, which held the lab password as a literal, was deleted.

🤖 Generated with Claude Code

… helper commands

A module that writes an environment's files (0600) and runs vault.deploy
for a tree from terraform apply, with credentials as literals or as
commands the CLI runs at deploy time; a lab and an AWS Secrets Manager
example; docs/terraform.md. bin/secrets/ holds the CyberArk CCP and
BeyondTrust Password Safe commands a <key>Command= reference can call.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@jcombs-pointblue
jcombs-pointblue merged commit e4e7f11 into master Oct 6, 2026
4 checks passed
@jcombs-pointblue
jcombs-pointblue deleted the claude/terraform-module branch October 6, 2026 01:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant