feat(ceph): add read-only metrics-worker RGW admin user + keys (#188)

This commit is contained in:
Andy Molenda
2026-06-26 14:07:49 +00:00
committed by GitHub
parent fa1683c9c6
commit 983e061d01
5 changed files with 72 additions and 2 deletions
+8 -2
View File
@@ -28,8 +28,14 @@ locals {
# Per-role generated-password length. ops is the break-glass account typed by
# hand at the KVM/console, so keep it short; dashboard/grafana are web logins
# (paste-friendly) and stay long. Roles not listed use the default.
ceph_password_length = { ops = 16 }
# (paste-friendly) and stay long. The metrics-worker RGW keys follow the
# AWS/RGW key shape (20-char access id, 40-char secret). Roles not listed use
# the default.
ceph_password_length = {
ops = 16
metrics_worker_access = 20
metrics_worker_secret = 40
}
ceph_password_default_length = 32
# Flatten (cluster, secret-role) -> { vault, title, length } across all
+5
View File
@@ -73,5 +73,10 @@ locals {
grafana = "${local.secret_prefix}_GRAFANA_PASSWORD"
s3_restic_access = "${local.secret_prefix}_S3_SVC_YUCCA_RESTIC_ACCESS_KEY"
s3_restic_secret = "${local.secret_prefix}_S3_SVC_YUCCA_RESTIC_SECRET_KEY"
# RGW admin (read-only) keys for the metrics worker. Titled <CLUSTER>_
# METRICS_WORKER_* (no _CEPH infix) to match the metrics-worker consumer's
# 1P contract, which is named by cluster, not by the ceph subsystem.
metrics_worker_access = "${upper(var.cluster_name)}_METRICS_WORKER_ACCESS_KEY"
metrics_worker_secret = "${upper(var.cluster_name)}_METRICS_WORKER_SECRET_KEY"
}
}
@@ -14,3 +14,5 @@ vault_ceph_dashboard_password: op://${vault}/${secrets.dashboard}/password
vault_grafana_admin_password: op://${vault}/${secrets.grafana}/password
vault_s3_restic_access_key: op://${vault}/${secrets.s3_restic_access}/password
vault_s3_restic_secret_key: op://${vault}/${secrets.s3_restic_secret}/password
vault_metrics_worker_access_key: op://${vault}/${secrets.metrics_worker_access}/password
vault_metrics_worker_secret_key: op://${vault}/${secrets.metrics_worker_secret}/password