CYBER-0 changes to secret management from stored config to individual variables
This commit is contained in:
@@ -48,7 +48,13 @@ The pipeline validates that `TARGET_ENVIRONMENT` matches `assets.yml`. A mismatc
|
||||
|
||||
## Secrets
|
||||
|
||||
The Ansible job requires `ANSIBLE_SECRET_VARS` as an environment-scoped GitLab **File** variable containing Ansible variables. SSH keys may be supplied as `ANSIBLE_PRIVATE_KEY_FILE`, also as a File variable.
|
||||
The Ansible job consumes credentials as individual environment-scoped GitLab
|
||||
**Variable** entries — `ANSIBLE_USER`, `ANSIBLE_PASSWORD`,
|
||||
`ANSIBLE_BECOME_PASSWORD`, `VCENTER_HOSTNAME`, `VCENTER_USERNAME`, and
|
||||
`VCENTER_PASSWORD` — plus an optional `ANSIBLE_PRIVATE_KEY` **File** variable
|
||||
for SSH key authentication. See [instructions.md](instructions.md) for a
|
||||
step-by-step setup guide and [docs/secrets.md](docs/secrets.md) for variable
|
||||
examples, masking guidance, and rotation.
|
||||
|
||||
Validation, normalization, and report jobs do not declare a GitLab environment and therefore do not receive environment-scoped credentials. See [docs/secrets.md](docs/secrets.md) for variable examples and rotation guidance.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user