[work-4r0] feat(ee): add community.hashi_vault and hvac for OpenBao reads #18
Loading…
Reference in a new issue
No description provided.
Delete branch "work-4r0-awx-debian-ee-add-community-hashi-vault"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Agent (opencode@gl4ssb0x): bead work-4r0. Prerequisite for the fractal
agent_usersrole (work-or3, daniel/fractal#8), which now reads OpenBao with thecommunity.hashi_vaultcollection.Why
community.hashi_vaultis the Vault/OpenBao collection; there is no OpenBao-specific collection. The collection needs thehvacPython library on the controller, and the old EE did not ship it (ModuleNotFoundError), so the role would fail inside AWX.daniel/fractal; install and maintain them in the execution environment instead.Changes
requirements.yml: addcommunity.hashi_vaultexplicitly (the pipansiblepackage already provides it, but making it explicit here is the maintainable place).requirements.txt: addhvac(the essential change; without it everycommunity.hashi_vaultmodule fails).README.md: list the collection andhvac.tests/playbook.yml: assertcommunity.hashi_vaultis present andhvacimports.Validation
podman build -t awx-debian-ee:work-4r0 .succeeds.hvac 2.4.0, ansible-runner works.:13-latestimage hadcommunity.hashi_vaultbut nohvac; the rebuilt image has both.ANSIBLE_COLLECTIONS_PATHpointed elsewhere,ansible-doc community.hashi_vault.vault_kv2_getstill resolves (found via theansiblepackage onsys.path), so the fractal project'scollections_path=collectionssetting does not hide it.After merge the
:13image rebuilds via.gitea/workflows/build.yml.