Compare commits
4 Commits
vibe/batch
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
| 02ca56358d | |||
| 3fee1e9ed7 | |||
| 3be6a2b7ef | |||
| 03a47396c5 |
60
.gitea/workflows/vault.yaml
Normal file
60
.gitea/workflows/vault.yaml
Normal file
@@ -0,0 +1,60 @@
|
|||||||
|
---
|
||||||
|
name: Hashicorp Vault
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_dispatch: {}
|
||||||
|
push: &vaultPaths
|
||||||
|
paths:
|
||||||
|
- 'iac/*.tf'
|
||||||
|
pull_request: *vaultPaths
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: ${{ github.ref }}-${{ github.workflow }}
|
||||||
|
cancel-in-progress: true
|
||||||
|
|
||||||
|
.vault_step: &vault_step
|
||||||
|
name: read vault secret
|
||||||
|
uses: https://gitea.arcodange.lab/arcodange-org/vault-action.git@main
|
||||||
|
id: vault-secrets
|
||||||
|
with:
|
||||||
|
url: https://vault.arcodange.lab
|
||||||
|
caCertificate: ${{ secrets.HOMELAB_CA_CERT }}
|
||||||
|
jwtGiteaOIDC: ${{ needs.gitea_vault_auth.outputs.gitea_vault_jwt }}
|
||||||
|
role: gitea_cicd_dance-lessons-coach
|
||||||
|
method: jwt
|
||||||
|
path: gitea_jwt
|
||||||
|
secrets: |
|
||||||
|
kvv1/google/credentials credentials | GOOGLE_BACKEND_CREDENTIALS ;
|
||||||
|
kvv1/gitea/tofu_module_reader ssh_private_key | TERRAFORM_SSH_KEY ;
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
gitea_vault_auth:
|
||||||
|
name: Auth with gitea for vault
|
||||||
|
runs-on: ubuntu-latest-ca
|
||||||
|
outputs:
|
||||||
|
gitea_vault_jwt: ${{steps.gitea_vault_jwt.outputs.id_token}}
|
||||||
|
steps:
|
||||||
|
- name: Auth with gitea for vault
|
||||||
|
id: gitea_vault_jwt
|
||||||
|
run: |
|
||||||
|
echo -n "${{ secrets.vault_oauth__sh_b64 }}" | base64 -d | bash
|
||||||
|
|
||||||
|
tofu:
|
||||||
|
name: Tofu - Vault
|
||||||
|
needs:
|
||||||
|
- gitea_vault_auth
|
||||||
|
runs-on: ubuntu-latest-ca
|
||||||
|
env:
|
||||||
|
OPENTOFU_VERSION: 1.8.2
|
||||||
|
TERRAFORM_VAULT_AUTH_JWT: ${{ needs.gitea_vault_auth.outputs.gitea_vault_jwt }}
|
||||||
|
VAULT_CACERT: "${{ github.workspace }}/homelab.pem"
|
||||||
|
steps:
|
||||||
|
- *vault_step
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- name: prepare vault self signed cert
|
||||||
|
run: echo -n "${{ secrets.HOMELAB_CA_CERT }}" | base64 -d > $VAULT_CACERT
|
||||||
|
- name: terraform apply
|
||||||
|
uses: dflook/terraform-apply@v1
|
||||||
|
with:
|
||||||
|
path: iac
|
||||||
|
auto_approve: true
|
||||||
@@ -47,8 +47,12 @@ ingress:
|
|||||||
enabled: true
|
enabled: true
|
||||||
className: ""
|
className: ""
|
||||||
annotations:
|
annotations:
|
||||||
traefik.ingress.kubernetes.io/router.entrypoints: web
|
traefik.ingress.kubernetes.io/router.entrypoints: websecure
|
||||||
traefik.ingress.kubernetes.io/router.middlewares: kube-system-crowdsec@kubernetescrd
|
traefik.ingress.kubernetes.io/router.tls: "true"
|
||||||
|
traefik.ingress.kubernetes.io/router.tls.certresolver: letsencrypt
|
||||||
|
traefik.ingress.kubernetes.io/router.tls.domains.0.main: arcodange.lab
|
||||||
|
traefik.ingress.kubernetes.io/router.tls.domains.0.sans: dancecoachlessons.arcodange.lab
|
||||||
|
traefik.ingress.kubernetes.io/router.middlewares: localIp@file
|
||||||
hosts:
|
hosts:
|
||||||
- host: dancecoachlessons.arcodange.lab
|
- host: dancecoachlessons.arcodange.lab
|
||||||
paths:
|
paths:
|
||||||
|
|||||||
6
iac/backend.tf
Normal file
6
iac/backend.tf
Normal file
@@ -0,0 +1,6 @@
|
|||||||
|
terraform {
|
||||||
|
backend "gcs" {
|
||||||
|
bucket = "arcodange-tf"
|
||||||
|
prefix = "dance-lessons-coach/main"
|
||||||
|
}
|
||||||
|
}
|
||||||
10
iac/main.tf
Normal file
10
iac/main.tf
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
locals {
|
||||||
|
app = {
|
||||||
|
name = "dance-lessons-coach"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
module "app_roles" {
|
||||||
|
source = "git::ssh://git@192.168.1.202:2222/arcodange-org/tools.git//hashicorp-vault/iac/modules/app_roles?depth=1&ref=main"
|
||||||
|
name = local.app.name
|
||||||
|
}
|
||||||
17
iac/providers.tf
Normal file
17
iac/providers.tf
Normal file
@@ -0,0 +1,17 @@
|
|||||||
|
terraform {
|
||||||
|
required_providers {
|
||||||
|
vault = {
|
||||||
|
source = "vault"
|
||||||
|
version = "4.4.0"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
provider "vault" {
|
||||||
|
address = "https://vault.arcodange.lab"
|
||||||
|
auth_login_jwt {
|
||||||
|
# TERRAFORM_VAULT_AUTH_JWT environment variable, set by the gitea OIDC step
|
||||||
|
mount = "gitea_jwt"
|
||||||
|
role = "gitea_cicd_dance-lessons-coach"
|
||||||
|
}
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user