CYBER-0 changes to secret management from stored config to individual variables
This commit is contained in:
+25
-17
@@ -32,29 +32,37 @@ Do not enable `CI_DEBUG_TRACE` in pipelines that receive secrets.
|
||||
|
||||
## Ansible Variables
|
||||
|
||||
Create `ANSIBLE_SECRET_VARS` as an environment-scoped **File** variable. Its
|
||||
contents are an Ansible YAML or JSON variables file, for example:
|
||||
Define credentials as individual environment-scoped **Variable** entries (not a
|
||||
single File variable), under **Settings > CI/CD > Variables**:
|
||||
|
||||
```yaml
|
||||
ansible_user: "DOMAIN\\automation-user"
|
||||
ansible_password: "replace-in-gitlab"
|
||||
ansible_become_password: "replace-in-gitlab"
|
||||
vcenter_username: "automation@vsphere.local"
|
||||
vcenter_password: "replace-in-gitlab"
|
||||
```
|
||||
| GitLab variable | Ansible variable | Purpose |
|
||||
| --- | --- | --- |
|
||||
| `ANSIBLE_USER` | `ansible_user` | Login account |
|
||||
| `ANSIBLE_PASSWORD` | `ansible_password` | Login password |
|
||||
| `ANSIBLE_BECOME_PASSWORD` | `ansible_become_password` | Sudo / enable password |
|
||||
| `VCENTER_HOSTNAME` | `vcenter_hostname` | vCenter appliance address |
|
||||
| `VCENTER_USERNAME` | `vcenter_username` | vCenter account |
|
||||
| `VCENTER_PASSWORD` | `vcenter_password` | vCenter password |
|
||||
|
||||
The `test:ansible` job checks that the variable resolves to a file and exports
|
||||
its temporary path as `ANSIBLE_VARS_FILE`. The methodology runner passes it with
|
||||
`--extra-vars @<file>` without printing the contents or putting values in the
|
||||
process command line.
|
||||
Set only those required by the target types declared in `assets.yml`. Values
|
||||
containing spaces or special characters (for example a Windows `DOMAIN\user`
|
||||
password) must use **Masked and hidden** (GitLab 15.10+); standard **Masked**
|
||||
rejects such formats.
|
||||
|
||||
For SSH key authentication, add `ANSIBLE_PRIVATE_KEY_FILE` as a separate
|
||||
environment-scoped **File** variable. The methodology runner passes that path through
|
||||
`--private-key` when present.
|
||||
The `test:ansible` job runs `methodologies/ansible/scripts/build-secrets.py`,
|
||||
which maps these variables to their Ansible names and writes a temporary YAML
|
||||
vars file. `run.sh` passes that file with `--extra-vars @<file>` without
|
||||
printing the contents or putting values in the process command line. The
|
||||
temporary files live under `$CI_PROJECT_DIR/.run/secrets/` and are removed when
|
||||
the job pod ends; they are never stored in artifacts.
|
||||
|
||||
For SSH key authentication, add `ANSIBLE_PRIVATE_KEY` as a separate
|
||||
environment-scoped **File** variable. The job writes its contents to a `0600`
|
||||
temporary key file and passes that path through `--private-key` when present.
|
||||
|
||||
The current job assumes one credential set per test environment. Environments
|
||||
with distinct Windows, Linux, network, or hypervisor credentials should be split
|
||||
into separate tool jobs, each referencing its own scoped File variable.
|
||||
into separate tool jobs, each referencing its own environment-scoped variables.
|
||||
|
||||
## ZAP Variables
|
||||
|
||||
|
||||
Reference in New Issue
Block a user