data.terraform_remote_state.cost_reporting[0]: Reading...
data.terraform_remote_state.gha_runner: Reading...
data.terraform_remote_state.kraftor: Reading...
data.terraform_remote_state.service_user_groups: Reading...
data.github_repository.repo: Reading...
tls_private_key.repo_key[0]: Refreshing state... [id=33db9961951e2b92c8a6418fa9da07a789f53317]
data.vault_policy_document.kraftor_ai_cost_allocation_policy: Reading...
data.vault_policy_document.kraftor_auth0_eval_policy: Reading...
data.vault_policy_document.kraftor_policy: Reading...
data.vault_policy_document.kraftor_auth0_eval_policy: Read complete after 0s [id=4076189050]
data.vault_policy_document.kraftor_ai_cost_allocation_policy: Read complete after 0s [id=3961277545]
data.vault_policy_document.kraftor_policy: Read complete after 0s [id=2931756898]
data.vault_policy_document.kraftor_datadog_monitoring_policy: Reading...
github_repository_deploy_key.eks_cluster_applications_key[0]: Refreshing state... [id=eks-cluster-applications:141727572]
vault_policy.kraftor_ai_cost_allocation_policy: Refreshing state... [id=kraftor-ai-cost-allocation-policy]
data.vault_policy_document.kraftor_datadog_monitoring_policy: Read complete after 0s [id=4212759260]
vault_policy.kraftor_policy: Refreshing state... [id=kraftor-policy]
vault_policy.kraftor_datadog_monitoring_policy: Refreshing state... [id=kraftor-datadog-monitoring-policy]
data.terraform_remote_state.service_user_groups: Read complete after 0s
data.terraform_remote_state.gha_runner: Read complete after 0s
vault_jwt_auth_backend_role.gha_datadog_monitoring_oidc_role: Refreshing state... [id=auth/ghav2/role/kraftor_datadog_monitoring_role]
vault_jwt_auth_backend_role.gha_ai_cost_allocation_oidc_role: Refreshing state... [id=auth/ghav2/role/kraftor_ai_cost_allocation_role]
vault_jwt_auth_backend_role.gha_oidc_role: Refreshing state... [id=auth/ghav2/role/kraftor_secrets_role]
aws_iam_group.kraftor_datadog_monitoring_tfstate[0]: Refreshing state... [id=kraftor-datadog-monitoring-tfstate]
module.deployment_user.aws_iam_user.iam_user: Refreshing state... [id=kraftor-cicd-user]
aws_iam_group.kraftor_cost_export_read[0]: Refreshing state... [id=kraftor-cost-export-read]
data.aws_iam_policy_document.kraftor_datadog_monitoring_tfstate[0]: Reading...
data.terraform_remote_state.cost_reporting[0]: Read complete after 0s
data.aws_iam_policy_document.kraftor_datadog_monitoring_tfstate[0]: Read complete after 0s [id=4065386327]
data.aws_iam_policy_document.kraftor_cost_export_read[0]: Reading...
aws_iam_policy.kraftor_datadog_monitoring_tfstate[0]: Refreshing state... [id=arn:aws:iam::176647218704:policy/kraftor-datadog-monitoring-tfstate]
data.aws_iam_policy_document.kraftor_cost_export_read[0]: Read complete after 0s [id=1827180508]
data.terraform_remote_state.kraftor: Read complete after 0s
aws_iam_policy.kraftor_cost_export_read[0]: Refreshing state... [id=arn:aws:iam::176647218704:policy/kraftor-cost-export-read]
data.github_repository.repo: Read complete after 0s
github_actions_secret.deploy_key[0]: Refreshing state... [id=kraftor:EKS_CLUSTER_APPLICATIONS_DEPLOY_KEY]
github_actions_secret.eval_creator_email[0]: Refreshing state... [id=kraftor:EVAL_CREATOR_EMAIL]
github_actions_secret.aws_role_arn[0]: Refreshing state... [id=kraftor:AWS_ROLE_ARN]
module.deployment_user.aws_iam_access_key.user[0]: Refreshing state... [id=AKIASSIH6UYIIXLTM2GX]
aws_iam_user_group_membership.cicd_ecr_push: Refreshing state... [id=terraform-20260131075924449100000001]
module.deployment_user.module.vault_secret[0].vault_generic_secret.secret[0]: Refreshing state... [id=infrastructure/root/repo-secrets-kraftor/iam-user-kraftor-cicd-user/automated/key]
data.vault_generic_secret.deployment_user_keys: Reading...
data.vault_generic_secret.deployment_user_keys: Read complete after 0s [id=infrastructure/root/repo-secrets-kraftor/iam-user-kraftor-cicd-user/automated/key]
module.ecr_deployment_secrets.vault_generic_secret.secret[0]: Refreshing state... [id=cicd/kraftor/automated/iam_user]
aws_iam_group_policy_attachment.kraftor_datadog_monitoring_tfstate[0]: Refreshing state... [id=kraftor-datadog-monitoring-tfstate-20260813143639263100000001]
aws_iam_group_policy_attachment.kraftor_cost_export_read[0]: Refreshing state... [id=kraftor-cost-export-read-20260831170136924400000001]
Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
+ create
~ update in-place
Terraform planned the following actions, but then encountered a problem:
# github_repository_deploy_key.eks_cluster_applications_key[0] will be created
+ resource "github_repository_deploy_key" "eks_cluster_applications_key" {
+ etag = (known after apply)
+ id = (known after apply)
+ key = <<-EOT
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDgh3nhbf+JKi1Rh6ILe5yb4cLx4XEDreJU6oEmgyCa+6sgBpSjK25wC2qu2F8VTPUJCYknsQYdMLrW/8Sgl4p/B/4qJ/hgPqdoQ0j+b3kFW3kNUT7ifODmKUtIfbiZBpoGDrRmnmMo1pgyAQAQeAPPn4syRVw+ejbDhZUiFwRJhItJfc6kaJlEIZHCt7kair/0T0U9rgKulq8vCoLzks0AijZ5oA3ArHB9PojIOsHzoX/X2usQwxTeuSGkV6FTnWV6Nwfb0dRUXD3sqAWZaUSSuFX1AuDxs/l/5MuMzaa9zvdAjTPAgfpNowDIVfifc60WyBAHBuLDtAWwxXREMbCn
EOT
+ read_only = false
+ repository = "eks-cluster-applications"
+ title = "kraftor deploy key"
}
# vault_jwt_auth_backend_role.gha_auth0_eval_oidc_role will be created
+ resource "vault_jwt_auth_backend_role" "gha_auth0_eval_oidc_role" {
+ backend = "ghav2"
+ bound_audiences = [
+ "https://github.com/FirstResonance",
]
+ bound_claims = {
+ "job_workflow_ref" = "FirstResonance/kraftor/.github/workflows/iic-eval.yaml@*,FirstResonance/kraftor/.github/workflows/deploy-inspect-dashboard.yaml@*"
}
+ bound_claims_type = "glob"
+ clock_skew_leeway = 0
+ disable_bound_claims_parsing = false
+ expiration_leeway = 0
+ id = (known after apply)
+ not_before_leeway = 0
+ role_name = "kraftor_auth0_eval_role"
+ role_type = "jwt"
+ token_policies = [
+ "kraftor-auth0-eval-policy",
]
+ token_ttl = 60
+ token_type = "default"
+ user_claim = "job_workflow_ref"
+ user_claim_json_pointer = false
+ verbose_oidc_logging = false
# (1 unchanged attribute hidden)
}
# vault_policy.kraftor_auth0_eval_policy will be created
+ resource "vault_policy" "kraftor_auth0_eval_policy" {
+ id = (known after apply)
+ name = "kraftor-auth0-eval-policy"
+ policy = <<-EOT
# Allow user to manage their own tokens
path "auth/token/create" {
capabilities = ["create", "read", "update", "list"]
}
# Auth0 credentials for the eval/load-test user pool
path "cicd/data/kraftor/automated/auth0-eval" {
capabilities = ["read"]
}
EOT
}
# vault_policy.kraftor_datadog_monitoring_policy will be updated in-place
~ resource "vault_policy" "kraftor_datadog_monitoring_policy" {
id = "kraftor-datadog-monitoring-policy"
name = "kraftor-datadog-monitoring-policy"
~ policy = <<-EOT
# Allow user to manage their own tokens
path "auth/token/create" {
capabilities = ["create", "read", "update", "list"]
}
# Allow kraftor Datadog monitoring Terraform to read backend credentials
path "cicd/data/kraftor/*" {
capabilities = ["list", "read"]
}
+ # Auth0 pool credentials are reachable only via kraftor_auth0_eval_role
+ path "cicd/data/kraftor/automated/auth0-eval" {
+ capabilities = ["deny"]
+ }
+
# Allow kraftor monitoring Terraform to read Datadog management credentials
path "global/data/datadog/secrets" {
capabilities = ["read"]
}
# Allow kraftor monitoring Terraform to inspect Datadog credential metadata
path "global/metadata/datadog/secrets" {
capabilities = ["read", "list"]
}
EOT
}
# vault_policy.kraftor_policy will be updated in-place
~ resource "vault_policy" "kraftor_policy" {
id = "kraftor-policy"
name = "kraftor-policy"
~ policy = <<-EOT
# Allow user to manage their own tokens
path "auth/token/create" {
capabilities = ["create", "read", "update", "list"]
}
# Allow kraftor to read its repo location
path "cicd/data/kraftor/*" {
capabilities = ["list", "read"]
}
+ # Auth0 pool credentials are reachable only via kraftor_auth0_eval_role
+ path "cicd/data/kraftor/automated/auth0-eval" {
+ capabilities = ["deny"]
+ }
+
# Allow kraftor to read app-specific secrets
path "applications/data/+/+/+/+/cicd-kraftor" {
capabilities = ["list", "read"]
}
# Allow kraftor to read infrastructure-specific secrets
path "infrastructure/data/+/+/+/+/cicd-kraftor" {
capabilities = ["list", "read"]
}
EOT
}
# module.auth0_eval_secrets.vault_kv_secret_v2.secret[0] will be created
+ resource "vault_kv_secret_v2" "secret" {
+ data = (sensitive value)
+ data_json_wo = (write-only attribute)
+ data_json_wo_version = 1
+ delete_all_versions = false
+ disable_read = false
+ id = (known after apply)
+ metadata = (known after apply)
+ mount = "cicd"
+ name = "kraftor/automated/auth0-eval"
+ path = (known after apply)
+ custom_metadata (known after apply)
}
Plan: 4 to add, 2 to change, 0 to destroy.
╷
│ Warning: Value for undeclared variable
│
│ The root module does not declare a variable named "key" but a value was
│ found in file "../accounts/vault-pub/backend.tfvars". If you meant to use
│ this value, add a "variable" block to the configuration.
│
│ To silence these warnings, use TF_VAR_... environment variables to provide
│ certain "global" settings to all configurations in your organization. To
│ reduce the verbosity of these warnings, use the -compact-warnings option.
╵
╷
│ Warning: Value for undeclared variable
│
│ The root module does not declare a variable named "bucket" but a value was
│ found in file "../accounts/vault-pub/backend.tfvars". If you meant to use
│ this value, add a "variable" block to the configuration.
│
│ To silence these warnings, use TF_VAR_... environment variables to provide
│ certain "global" settings to all configurations in your organization. To
│ reduce the verbosity of these warnings, use the -compact-warnings option.
╵
╷
│ Warning: Values for undeclared variables
│
│ In addition to the other similar warnings shown, 1 other variable(s)
│ defined without being declared.
╵
╷
│ Warning: Reference to undefined provider
│
│ on iam.tf line 46, in module "deployment_user":
│ 46: aws = aws.ecr
│
│ There is no explicit declaration for local provider name "aws" in
│ module.deployment_user, so Terraform is assuming you mean to pass a
│ configuration for "hashicorp/aws".
│
│ If you also control the child module, add a required_providers entry named
│ "aws" with the source address "hashicorp/aws".
╵
╷
│ Error: "repository": required field is not set
│
│ with github_actions_secret.deploy_key[0],
│ on eks-cluster-apps-key.tf line 29, in resource "github_actions_secret" "deploy_key":
│ 29: resource "github_actions_secret" "deploy_key" {
│
╵
╷
│ Error: "repository": required field is not set
│
│ with github_actions_secret.aws_role_arn[0],
│ on eval-secrets.tf line 16, in resource "github_actions_secret" "aws_role_arn":
│ 16: resource "github_actions_secret" "aws_role_arn" {
│
╵
╷
│ Error: "repository": required field is not set
│
│ with github_actions_secret.eval_creator_email[0],
│ on eval-secrets.tf line 23, in resource "github_actions_secret" "eval_creator_email":
│ 23: resource "github_actions_secret" "eval_creator_email" {
│
╵
Created
September 21, 2026 15:55
-
-
Save adrian-cacho-fr/9d83eb5369c7b598345f3cbc22d0f1f3 to your computer and use it in GitHub Desktop.
Terraform plan diff: repo-secrets-kraftor / vault-pub
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment