mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 21:37:50 +08:00
feat(ceph): add read-only metrics-worker RGW admin user + keys (#188)
This commit is contained in:
@@ -28,8 +28,14 @@ locals {
|
||||
|
||||
# Per-role generated-password length. ops is the break-glass account typed by
|
||||
# hand at the KVM/console, so keep it short; dashboard/grafana are web logins
|
||||
# (paste-friendly) and stay long. Roles not listed use the default.
|
||||
ceph_password_length = { ops = 16 }
|
||||
# (paste-friendly) and stay long. The metrics-worker RGW keys follow the
|
||||
# AWS/RGW key shape (20-char access id, 40-char secret). Roles not listed use
|
||||
# the default.
|
||||
ceph_password_length = {
|
||||
ops = 16
|
||||
metrics_worker_access = 20
|
||||
metrics_worker_secret = 40
|
||||
}
|
||||
ceph_password_default_length = 32
|
||||
|
||||
# Flatten (cluster, secret-role) -> { vault, title, length } across all
|
||||
|
||||
@@ -73,5 +73,10 @@ locals {
|
||||
grafana = "${local.secret_prefix}_GRAFANA_PASSWORD"
|
||||
s3_restic_access = "${local.secret_prefix}_S3_SVC_YUCCA_RESTIC_ACCESS_KEY"
|
||||
s3_restic_secret = "${local.secret_prefix}_S3_SVC_YUCCA_RESTIC_SECRET_KEY"
|
||||
# RGW admin (read-only) keys for the metrics worker. Titled <CLUSTER>_
|
||||
# METRICS_WORKER_* (no _CEPH infix) to match the metrics-worker consumer's
|
||||
# 1P contract, which is named by cluster, not by the ceph subsystem.
|
||||
metrics_worker_access = "${upper(var.cluster_name)}_METRICS_WORKER_ACCESS_KEY"
|
||||
metrics_worker_secret = "${upper(var.cluster_name)}_METRICS_WORKER_SECRET_KEY"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -14,3 +14,5 @@ vault_ceph_dashboard_password: op://${vault}/${secrets.dashboard}/password
|
||||
vault_grafana_admin_password: op://${vault}/${secrets.grafana}/password
|
||||
vault_s3_restic_access_key: op://${vault}/${secrets.s3_restic_access}/password
|
||||
vault_s3_restic_secret_key: op://${vault}/${secrets.s3_restic_secret}/password
|
||||
vault_metrics_worker_access_key: op://${vault}/${secrets.metrics_worker_access}/password
|
||||
vault_metrics_worker_secret_key: op://${vault}/${secrets.metrics_worker_secret}/password
|
||||
|
||||
Reference in New Issue
Block a user