Skip to content

[WIP] Feature/sscsi vp proxy cluster ca chart#119

Open
mhjacks wants to merge 23 commits intovalidatedpatterns:mainfrom
mhjacks:feature/sscsi-vp-proxy-cluster-ca-chart
Open

[WIP] Feature/sscsi vp proxy cluster ca chart#119
mhjacks wants to merge 23 commits intovalidatedpatterns:mainfrom
mhjacks:feature/sscsi-vp-proxy-cluster-ca-chart

Conversation

@mhjacks
Copy link
Copy Markdown
Collaborator

@mhjacks mhjacks commented May 5, 2026

Add mechanism to cluster_utils to create kubernetes auth for SS-CSI after the manner of ESO. CA trusts are expected to be provided separately

Martin Jackson added 23 commits April 28, 2026 14:31
- Read ssCsiWorkloadAuth from values-<clustergroup>.yaml applications
- Hub roles auth/hub/role/hub-sscsi-*; spoke roles per cluster vault_path
- New tasks: workload auth collection, spoke role loop; defaults for TTL and paths
- Legacy vault_csi_kubernetes_auth supported via synthetic hub row
- Include from vault_secrets_init and vault_spokes_init

Made-with: Cursor
- Default pattern_dir from PATTERN_DIR when unset (vault.yml had no pattern_settings).
- Alias main_clustergroupname from main_clustergroup after pattern_settings.
- Run pattern_settings before vault_utils in vault.yml so hub values file can load.
- Emit a single debug line with values path, app count, ssCsiWorkloadAuth identity count,
  and hub role count so operators can confirm SSCSI Vault auth wiring.

Made-with: Cursor
Parse clusterGroup.managedClusterGroups alongside applications from the
hub values file. For each group with a mapping applications.*.ssCsiWorkloadAuth,
reuse the same collection logic with cluster defaulting to group name
(managedClusterGroup.name, else YAML key) so spoke Vault roles match ACM.

Pass explicit hub default for clusterGroup.applications; thread default
through collect_one_entry for inner_item.cluster.

Made-with: Cursor
vault-only plays (e.g. collection vault.yml with only vault_utils) never set
pattern_dir or main_clustergroup, so ssCsiWorkloadAuth discovery saw an empty
values path. Include pattern_settings resolve_overrides and load
main.clusterGroupName from values-global when main_clustergroup is unset,
matching load_secrets / full vault play behavior.

Made-with: Cursor
Restore inline hub k8s_exec (apply_one task file was missing). When ssCsiWorkloadAuth
entry sets roleSlug, use it as the vault role suffix; otherwise keep SHA1 hash.

Spoke rows use the same rule so chart stable slugs can match Ansible.

Made-with: Cursor
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant