HomeDevCentral

Give access to Vault to Rhyne-Wyse automated agent

Description

Give access to Vault to Rhyne-Wyse automated agent

Summary:
Use of OpenTofu

Terraform / OpenTofu allows to provision virtually every aspect
of Vault / OpenBao, where Vault state module for Salt only handle
policies.

Last Friday, we devised how to integrate Terraform to our repository
to provision virtual machines to VMware ESXi. This provider follows
the same structure.

The README is short, as it's actually intended as sections to be added
to the upcoming VMWare ESXi change, written last Friday evening too.

Rhyne-Wyse access

The policy allows to connect to Agora and to the db-B cluster for
reports purpose. Access to db is strictly limited, see D3667.

Instead of storing that policy in Salt and only create AppRole
with OpenTofu, both are consolidated in one source.

Ref T2124

Test Plan:

  • Plan applied, vault policy read rhyne-wyse
  • AppRole tested with hvac

Maniphest Tasks: T2124

Differential Revision: https://devcentral.nasqueron.org/D3693

Details

Provenance
derecksonAuthored on Sep 19 2025, 01:44
derecksonPushed on Sat, Feb 7, 19:27
Differential Revision
D3693: Give access to Vault to Rhyne-Wyse automated agent
Parents
rOPSbec72977d1aa: Restore ops group previous state
Branches
Unknown
Tags
Unknown
Tasks
T2124: Update reports automatically on Agora