CYBER-0 changes to secret management from stored config to individual variables

This commit is contained in:
Ole Valente
2026-09-23 12:47:05 +02:00
parent edb6cde069
commit c42888086c
7 changed files with 275 additions and 22 deletions
+25 -17
View File
@@ -32,29 +32,37 @@ Do not enable `CI_DEBUG_TRACE` in pipelines that receive secrets.
## Ansible Variables
Create `ANSIBLE_SECRET_VARS` as an environment-scoped **File** variable. Its
contents are an Ansible YAML or JSON variables file, for example:
Define credentials as individual environment-scoped **Variable** entries (not a
single File variable), under **Settings > CI/CD > Variables**:
```yaml
ansible_user: "DOMAIN\\automation-user"
ansible_password: "replace-in-gitlab"
ansible_become_password: "replace-in-gitlab"
vcenter_username: "automation@vsphere.local"
vcenter_password: "replace-in-gitlab"
```
| GitLab variable | Ansible variable | Purpose |
| --- | --- | --- |
| `ANSIBLE_USER` | `ansible_user` | Login account |
| `ANSIBLE_PASSWORD` | `ansible_password` | Login password |
| `ANSIBLE_BECOME_PASSWORD` | `ansible_become_password` | Sudo / enable password |
| `VCENTER_HOSTNAME` | `vcenter_hostname` | vCenter appliance address |
| `VCENTER_USERNAME` | `vcenter_username` | vCenter account |
| `VCENTER_PASSWORD` | `vcenter_password` | vCenter password |
The `test:ansible` job checks that the variable resolves to a file and exports
its temporary path as `ANSIBLE_VARS_FILE`. The methodology runner passes it with
`--extra-vars @<file>` without printing the contents or putting values in the
process command line.
Set only those required by the target types declared in `assets.yml`. Values
containing spaces or special characters (for example a Windows `DOMAIN\user`
password) must use **Masked and hidden** (GitLab 15.10+); standard **Masked**
rejects such formats.
For SSH key authentication, add `ANSIBLE_PRIVATE_KEY_FILE` as a separate
environment-scoped **File** variable. The methodology runner passes that path through
`--private-key` when present.
The `test:ansible` job runs `methodologies/ansible/scripts/build-secrets.py`,
which maps these variables to their Ansible names and writes a temporary YAML
vars file. `run.sh` passes that file with `--extra-vars @<file>` without
printing the contents or putting values in the process command line. The
temporary files live under `$CI_PROJECT_DIR/.run/secrets/` and are removed when
the job pod ends; they are never stored in artifacts.
For SSH key authentication, add `ANSIBLE_PRIVATE_KEY` as a separate
environment-scoped **File** variable. The job writes its contents to a `0600`
temporary key file and passes that path through `--private-key` when present.
The current job assumes one credential set per test environment. Environments
with distinct Windows, Linux, network, or hypervisor credentials should be split
into separate tool jobs, each referencing its own scoped File variable.
into separate tool jobs, each referencing its own environment-scoped variables.
## ZAP Variables