CYBER-0 changes to secret management from stored config to individual variables

This commit is contained in:
Ole Valente
2026-09-23 12:47:05 +02:00
parent edb6cde069
commit c42888086c
7 changed files with 275 additions and 22 deletions
+7 -1
View File
@@ -48,7 +48,13 @@ The pipeline validates that `TARGET_ENVIRONMENT` matches `assets.yml`. A mismatc
## Secrets
The Ansible job requires `ANSIBLE_SECRET_VARS` as an environment-scoped GitLab **File** variable containing Ansible variables. SSH keys may be supplied as `ANSIBLE_PRIVATE_KEY_FILE`, also as a File variable.
The Ansible job consumes credentials as individual environment-scoped GitLab
**Variable** entries — `ANSIBLE_USER`, `ANSIBLE_PASSWORD`,
`ANSIBLE_BECOME_PASSWORD`, `VCENTER_HOSTNAME`, `VCENTER_USERNAME`, and
`VCENTER_PASSWORD` — plus an optional `ANSIBLE_PRIVATE_KEY` **File** variable
for SSH key authentication. See [instructions.md](instructions.md) for a
step-by-step setup guide and [docs/secrets.md](docs/secrets.md) for variable
examples, masking guidance, and rotation.
Validation, normalization, and report jobs do not declare a GitLab environment and therefore do not receive environment-scoped credentials. See [docs/secrets.md](docs/secrets.md) for variable examples and rotation guidance.