CYBER-0 changes to secret management from stored config to individual variables

This commit is contained in:
Ole Valente
2026-09-23 12:47:05 +02:00
parent edb6cde069
commit c42888086c
7 changed files with 275 additions and 22 deletions
+8 -4
View File
@@ -109,10 +109,14 @@ test:ansible:
name: "$TARGET_ENVIRONMENT"
action: verify
script:
- test -n "${ANSIBLE_SECRET_VARS:-}" || { echo "ANSIBLE_SECRET_VARS file variable is required" >&2; exit 1; }
- test -f "$ANSIBLE_SECRET_VARS" || { echo "ANSIBLE_SECRET_VARS must be a GitLab file variable" >&2; exit 1; }
- export ANSIBLE_VARS_FILE="$ANSIBLE_SECRET_VARS"
- bash methodologies/ansible/run.sh --limit "${ANSIBLE_LIMIT:-all}"
- |
SECRETS_DIR="$CI_PROJECT_DIR/.run/secrets"
python3 methodologies/ansible/scripts/build-secrets.py --out-dir "$SECRETS_DIR"
export ANSIBLE_VARS_FILE="$SECRETS_DIR/ansible-vars.yml"
if [ -f "$SECRETS_DIR/ansible-private-key" ]; then
export ANSIBLE_PRIVATE_KEY_FILE="$SECRETS_DIR/ansible-private-key"
fi
bash methodologies/ansible/run.sh --limit "${ANSIBLE_LIMIT:-all}"
artifacts:
when: always
expire_in: 90 days