Skip to content

Instantly share code, notes, and snippets.

@adrian-cacho-fr
Created September 21, 2026 15:55
Show Gist options
  • Select an option

  • Save adrian-cacho-fr/9d83eb5369c7b598345f3cbc22d0f1f3 to your computer and use it in GitHub Desktop.

Select an option

Save adrian-cacho-fr/9d83eb5369c7b598345f3cbc22d0f1f3 to your computer and use it in GitHub Desktop.
Terraform plan diff: repo-secrets-kraftor / vault-pub
data.terraform_remote_state.cost_reporting[0]: Reading...
data.terraform_remote_state.gha_runner: Reading...
data.terraform_remote_state.kraftor: Reading...
data.terraform_remote_state.service_user_groups: Reading...
data.github_repository.repo: Reading...
tls_private_key.repo_key[0]: Refreshing state... [id=33db9961951e2b92c8a6418fa9da07a789f53317]
data.vault_policy_document.kraftor_ai_cost_allocation_policy: Reading...
data.vault_policy_document.kraftor_auth0_eval_policy: Reading...
data.vault_policy_document.kraftor_policy: Reading...
data.vault_policy_document.kraftor_auth0_eval_policy: Read complete after 0s [id=4076189050]
data.vault_policy_document.kraftor_ai_cost_allocation_policy: Read complete after 0s [id=3961277545]
data.vault_policy_document.kraftor_policy: Read complete after 0s [id=2931756898]
data.vault_policy_document.kraftor_datadog_monitoring_policy: Reading...
github_repository_deploy_key.eks_cluster_applications_key[0]: Refreshing state... [id=eks-cluster-applications:141727572]
vault_policy.kraftor_ai_cost_allocation_policy: Refreshing state... [id=kraftor-ai-cost-allocation-policy]
data.vault_policy_document.kraftor_datadog_monitoring_policy: Read complete after 0s [id=4212759260]
vault_policy.kraftor_policy: Refreshing state... [id=kraftor-policy]
vault_policy.kraftor_datadog_monitoring_policy: Refreshing state... [id=kraftor-datadog-monitoring-policy]
data.terraform_remote_state.service_user_groups: Read complete after 0s
data.terraform_remote_state.gha_runner: Read complete after 0s
vault_jwt_auth_backend_role.gha_datadog_monitoring_oidc_role: Refreshing state... [id=auth/ghav2/role/kraftor_datadog_monitoring_role]
vault_jwt_auth_backend_role.gha_ai_cost_allocation_oidc_role: Refreshing state... [id=auth/ghav2/role/kraftor_ai_cost_allocation_role]
vault_jwt_auth_backend_role.gha_oidc_role: Refreshing state... [id=auth/ghav2/role/kraftor_secrets_role]
aws_iam_group.kraftor_datadog_monitoring_tfstate[0]: Refreshing state... [id=kraftor-datadog-monitoring-tfstate]
module.deployment_user.aws_iam_user.iam_user: Refreshing state... [id=kraftor-cicd-user]
aws_iam_group.kraftor_cost_export_read[0]: Refreshing state... [id=kraftor-cost-export-read]
data.aws_iam_policy_document.kraftor_datadog_monitoring_tfstate[0]: Reading...
data.terraform_remote_state.cost_reporting[0]: Read complete after 0s
data.aws_iam_policy_document.kraftor_datadog_monitoring_tfstate[0]: Read complete after 0s [id=4065386327]
data.aws_iam_policy_document.kraftor_cost_export_read[0]: Reading...
aws_iam_policy.kraftor_datadog_monitoring_tfstate[0]: Refreshing state... [id=arn:aws:iam::176647218704:policy/kraftor-datadog-monitoring-tfstate]
data.aws_iam_policy_document.kraftor_cost_export_read[0]: Read complete after 0s [id=1827180508]
data.terraform_remote_state.kraftor: Read complete after 0s
aws_iam_policy.kraftor_cost_export_read[0]: Refreshing state... [id=arn:aws:iam::176647218704:policy/kraftor-cost-export-read]
data.github_repository.repo: Read complete after 0s
github_actions_secret.deploy_key[0]: Refreshing state... [id=kraftor:EKS_CLUSTER_APPLICATIONS_DEPLOY_KEY]
github_actions_secret.eval_creator_email[0]: Refreshing state... [id=kraftor:EVAL_CREATOR_EMAIL]
github_actions_secret.aws_role_arn[0]: Refreshing state... [id=kraftor:AWS_ROLE_ARN]
module.deployment_user.aws_iam_access_key.user[0]: Refreshing state... [id=AKIASSIH6UYIIXLTM2GX]
aws_iam_user_group_membership.cicd_ecr_push: Refreshing state... [id=terraform-20260131075924449100000001]
module.deployment_user.module.vault_secret[0].vault_generic_secret.secret[0]: Refreshing state... [id=infrastructure/root/repo-secrets-kraftor/iam-user-kraftor-cicd-user/automated/key]
data.vault_generic_secret.deployment_user_keys: Reading...
data.vault_generic_secret.deployment_user_keys: Read complete after 0s [id=infrastructure/root/repo-secrets-kraftor/iam-user-kraftor-cicd-user/automated/key]
module.ecr_deployment_secrets.vault_generic_secret.secret[0]: Refreshing state... [id=cicd/kraftor/automated/iam_user]
aws_iam_group_policy_attachment.kraftor_datadog_monitoring_tfstate[0]: Refreshing state... [id=kraftor-datadog-monitoring-tfstate-20260813143639263100000001]
aws_iam_group_policy_attachment.kraftor_cost_export_read[0]: Refreshing state... [id=kraftor-cost-export-read-20260831170136924400000001]

Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  + create
  ~ update in-place

Terraform planned the following actions, but then encountered a problem:

  # github_repository_deploy_key.eks_cluster_applications_key[0] will be created
  + resource "github_repository_deploy_key" "eks_cluster_applications_key" {
      + etag       = (known after apply)
      + id         = (known after apply)
      + key        = <<-EOT
            ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDgh3nhbf+JKi1Rh6ILe5yb4cLx4XEDreJU6oEmgyCa+6sgBpSjK25wC2qu2F8VTPUJCYknsQYdMLrW/8Sgl4p/B/4qJ/hgPqdoQ0j+b3kFW3kNUT7ifODmKUtIfbiZBpoGDrRmnmMo1pgyAQAQeAPPn4syRVw+ejbDhZUiFwRJhItJfc6kaJlEIZHCt7kair/0T0U9rgKulq8vCoLzks0AijZ5oA3ArHB9PojIOsHzoX/X2usQwxTeuSGkV6FTnWV6Nwfb0dRUXD3sqAWZaUSSuFX1AuDxs/l/5MuMzaa9zvdAjTPAgfpNowDIVfifc60WyBAHBuLDtAWwxXREMbCn
        EOT
      + read_only  = false
      + repository = "eks-cluster-applications"
      + title      = "kraftor deploy key"
    }

  # vault_jwt_auth_backend_role.gha_auth0_eval_oidc_role will be created
  + resource "vault_jwt_auth_backend_role" "gha_auth0_eval_oidc_role" {
      + backend                      = "ghav2"
      + bound_audiences              = [
          + "https://github.com/FirstResonance",
        ]
      + bound_claims                 = {
          + "job_workflow_ref" = "FirstResonance/kraftor/.github/workflows/iic-eval.yaml@*,FirstResonance/kraftor/.github/workflows/deploy-inspect-dashboard.yaml@*"
        }
      + bound_claims_type            = "glob"
      + clock_skew_leeway            = 0
      + disable_bound_claims_parsing = false
      + expiration_leeway            = 0
      + id                           = (known after apply)
      + not_before_leeway            = 0
      + role_name                    = "kraftor_auth0_eval_role"
      + role_type                    = "jwt"
      + token_policies               = [
          + "kraftor-auth0-eval-policy",
        ]
      + token_ttl                    = 60
      + token_type                   = "default"
      + user_claim                   = "job_workflow_ref"
      + user_claim_json_pointer      = false
      + verbose_oidc_logging         = false
        # (1 unchanged attribute hidden)
    }

  # vault_policy.kraftor_auth0_eval_policy will be created
  + resource "vault_policy" "kraftor_auth0_eval_policy" {
      + id     = (known after apply)
      + name   = "kraftor-auth0-eval-policy"
      + policy = <<-EOT
            # Allow user to manage their own tokens
            path "auth/token/create" {
              capabilities = ["create", "read", "update", "list"]
            }
            
            # Auth0 credentials for the eval/load-test user pool
            path "cicd/data/kraftor/automated/auth0-eval" {
              capabilities = ["read"]
            }
        EOT
    }

  # vault_policy.kraftor_datadog_monitoring_policy will be updated in-place
  ~ resource "vault_policy" "kraftor_datadog_monitoring_policy" {
        id     = "kraftor-datadog-monitoring-policy"
        name   = "kraftor-datadog-monitoring-policy"
      ~ policy = <<-EOT
            # Allow user to manage their own tokens
            path "auth/token/create" {
              capabilities = ["create", "read", "update", "list"]
            }
            
            # Allow kraftor Datadog monitoring Terraform to read backend credentials
            path "cicd/data/kraftor/*" {
              capabilities = ["list", "read"]
            }
            
          + # Auth0 pool credentials are reachable only via kraftor_auth0_eval_role
          + path "cicd/data/kraftor/automated/auth0-eval" {
          +   capabilities = ["deny"]
          + }
          + 
            # Allow kraftor monitoring Terraform to read Datadog management credentials
            path "global/data/datadog/secrets" {
              capabilities = ["read"]
            }
            
            # Allow kraftor monitoring Terraform to inspect Datadog credential metadata
            path "global/metadata/datadog/secrets" {
              capabilities = ["read", "list"]
            }
        EOT
    }

  # vault_policy.kraftor_policy will be updated in-place
  ~ resource "vault_policy" "kraftor_policy" {
        id     = "kraftor-policy"
        name   = "kraftor-policy"
      ~ policy = <<-EOT
            # Allow user to manage their own tokens
            path "auth/token/create" {
              capabilities = ["create", "read", "update", "list"]
            }
            
            # Allow kraftor to read its repo location
            path "cicd/data/kraftor/*" {
              capabilities = ["list", "read"]
            }
            
          + # Auth0 pool credentials are reachable only via kraftor_auth0_eval_role
          + path "cicd/data/kraftor/automated/auth0-eval" {
          +   capabilities = ["deny"]
          + }
          + 
            # Allow kraftor to read app-specific secrets
            path "applications/data/+/+/+/+/cicd-kraftor" {
              capabilities = ["list", "read"]
            }
            
            # Allow kraftor to read infrastructure-specific secrets
            path "infrastructure/data/+/+/+/+/cicd-kraftor" {
              capabilities = ["list", "read"]
            }
        EOT
    }

  # module.auth0_eval_secrets.vault_kv_secret_v2.secret[0] will be created
  + resource "vault_kv_secret_v2" "secret" {
      + data                 = (sensitive value)
      + data_json_wo         = (write-only attribute)
      + data_json_wo_version = 1
      + delete_all_versions  = false
      + disable_read         = false
      + id                   = (known after apply)
      + metadata             = (known after apply)
      + mount                = "cicd"
      + name                 = "kraftor/automated/auth0-eval"
      + path                 = (known after apply)

      + custom_metadata (known after apply)
    }

Plan: 4 to add, 2 to change, 0 to destroy.
╷
│ Warning: Value for undeclared variable
│ 
│ The root module does not declare a variable named "key" but a value was
│ found in file "../accounts/vault-pub/backend.tfvars". If you meant to use
│ this value, add a "variable" block to the configuration.
│ 
│ To silence these warnings, use TF_VAR_... environment variables to provide
│ certain "global" settings to all configurations in your organization. To
│ reduce the verbosity of these warnings, use the -compact-warnings option.
╵
╷
│ Warning: Value for undeclared variable
│ 
│ The root module does not declare a variable named "bucket" but a value was
│ found in file "../accounts/vault-pub/backend.tfvars". If you meant to use
│ this value, add a "variable" block to the configuration.
│ 
│ To silence these warnings, use TF_VAR_... environment variables to provide
│ certain "global" settings to all configurations in your organization. To
│ reduce the verbosity of these warnings, use the -compact-warnings option.
╵
╷
│ Warning: Values for undeclared variables
│ 
│ In addition to the other similar warnings shown, 1 other variable(s)
│ defined without being declared.
╵
╷
│ Warning: Reference to undefined provider
│ 
│   on iam.tf line 46, in module "deployment_user":46:     aws = aws.ecr
│ 
│ There is no explicit declaration for local provider name "aws" in
│ module.deployment_user, so Terraform is assuming you mean to pass a
│ configuration for "hashicorp/aws".
│ 
│ If you also control the child module, add a required_providers entry named
│ "aws" with the source address "hashicorp/aws".
╵
╷
│ Error: "repository": required field is not set
│ 
│   with github_actions_secret.deploy_key[0],
│   on eks-cluster-apps-key.tf line 29, in resource "github_actions_secret" "deploy_key":29: resource "github_actions_secret" "deploy_key" {
│ 
╵
╷
│ Error: "repository": required field is not set
│ 
│   with github_actions_secret.aws_role_arn[0],
│   on eval-secrets.tf line 16, in resource "github_actions_secret" "aws_role_arn":16: resource "github_actions_secret" "aws_role_arn" {
│ 
╵
╷
│ Error: "repository": required field is not set
│ 
│   with github_actions_secret.eval_creator_email[0],
│   on eval-secrets.tf line 23, in resource "github_actions_secret" "eval_creator_email":23: resource "github_actions_secret" "eval_creator_email" {
│ 
╵
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment