From 5747228f8c7c793dcf62a94aeb11fdb96ee7a37e Mon Sep 17 00:00:00 2001 From: pmikus Date: Fri, 29 Oct 2021 06:19:46 +0000 Subject: feat(Terraform): AWS backend role migration Signed-off-by: pmikus Change-Id: I8c93eaaa766c48b705a19e38123b69c994669dc0 --- fdio.infra.terraform/1n_nmd/aws/main.tf | 37 ----------------- fdio.infra.terraform/1n_nmd/aws/providers.tf | 14 ------- fdio.infra.terraform/1n_nmd/aws/variables.tf | 11 ----- .../1n_nmd/tools/artifacts_download.py | 47 ---------------------- .../1n_nmd/vault-aws-secret-backend/main.tf | 37 +++++++++++++++++ .../1n_nmd/vault-aws-secret-backend/providers.tf | 5 +++ .../1n_nmd/vault-aws-secret-backend/variables.tf | 23 +++++++++++ .../1n_nmd/vault-aws-secret-backend/versions.tf | 13 ++++++ 8 files changed, 78 insertions(+), 109 deletions(-) delete mode 100644 fdio.infra.terraform/1n_nmd/aws/main.tf delete mode 100644 fdio.infra.terraform/1n_nmd/aws/providers.tf delete mode 100644 fdio.infra.terraform/1n_nmd/aws/variables.tf delete mode 100755 fdio.infra.terraform/1n_nmd/tools/artifacts_download.py create mode 100644 fdio.infra.terraform/1n_nmd/vault-aws-secret-backend/main.tf create mode 100644 fdio.infra.terraform/1n_nmd/vault-aws-secret-backend/providers.tf create mode 100644 fdio.infra.terraform/1n_nmd/vault-aws-secret-backend/variables.tf create mode 100644 fdio.infra.terraform/1n_nmd/vault-aws-secret-backend/versions.tf (limited to 'fdio.infra.terraform/1n_nmd') diff --git a/fdio.infra.terraform/1n_nmd/aws/main.tf b/fdio.infra.terraform/1n_nmd/aws/main.tf deleted file mode 100644 index be7eb7c577..0000000000 --- a/fdio.infra.terraform/1n_nmd/aws/main.tf +++ /dev/null @@ -1,37 +0,0 @@ -resource "vault_aws_secret_backend" "aws" { - access_key = var.aws_access_key - secret_key = var.aws_secret_key - path = "${var.name}-path" - - default_lease_ttl_seconds = "43200" - max_lease_ttl_seconds = "43200" -} - -resource "vault_aws_secret_backend_role" "admin" { - backend = vault_aws_secret_backend.aws.path - name = "${var.name}-role" - credential_type = "iam_user" - - policy_document = <