Skip to content

feat: wire OpenBao KMS auto-unseal secrets on scaleway, add external-dns IAM#44

Merged
nbrieussel merged 1 commit into
mainfrom
feat/scaleway-openbao-dns
Jul 21, 2026
Merged

feat: wire OpenBao KMS auto-unseal secrets on scaleway, add external-dns IAM#44
nbrieussel merged 1 commit into
mainfrom
feat/scaleway-openbao-dns

Conversation

@nbrieussel

Copy link
Copy Markdown
Contributor

Summary

  • 02-cluster/scaleway: creates the openbao-unseal-aws and scaleway-s3-credentials Secrets (mirrors 02-cluster/local), needed by the gitops-side seal "awskms" fix
  • 04-dns/scaleway: new terraform root provisioning the external-dns IAM application/policy/API key (DomainsDNSFullAccess), output-only — no automated secret push yet

Test plan

  • terraform fmt / validate / providers lock on 04-dns/scaleway
  • Applied live; OpenBao now auto-unseals on scaleway-homelab and the external-dns workload credentials exist

🤖 Generated with Claude Code

…dns IAM

- 02-cluster/scaleway: create the openbao namespace + scaleway-s3-credentials
  and openbao-unseal-aws secrets (mirrors 02-cluster/local), drop Infisical
  in favor of a plain argocd_admin_password_hash var
- 04-dns/scaleway: new IAM root for the external-dns workload identity
  (DomainsDNSFullAccess, scoped to the project), output-only for now

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CCgyeSfKWH6m5mmJEg6t43
@nbrieussel
nbrieussel merged commit a326d58 into main Jul 21, 2026
4 of 6 checks passed
@nbrieussel
nbrieussel deleted the feat/scaleway-openbao-dns branch July 21, 2026 14:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant