diff --git a/modules/keyvault/main.tf b/modules/keyvault/main.tf index 8fc7d25..a071c72 100644 --- a/modules/keyvault/main.tf +++ b/modules/keyvault/main.tf @@ -18,7 +18,7 @@ data "azuread_application" "CI_app_registration" { } -resource "azurerm_key_vault_access_policy" "current" { +resource "azurerm_key_vault_access_policy" "CI" { key_vault_id = azurerm_key_vault.keyvault.id tenant_id = data.azurerm_client_config.current.tenant_id object_id = data.azuread_application.CI_app_registration.id @@ -66,84 +66,71 @@ resource "azurerm_key_vault_access_policy" "admin" { data "azurerm_key_vault_secret" "strapi_admin_jwt_secret" { name = "strapi-admin-jwt-secret" key_vault_id = azurerm_key_vault.keyvault.id - depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.current] + depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.CI] } data "azurerm_key_vault_secret" "strapi_jwt_secret" { name = "strapi-jwt-secret" key_vault_id = azurerm_key_vault.keyvault.id - depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.current] + depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.CI] } data "azurerm_key_vault_secret" "strapi_api_token_salt" { name = "strapi-api-token-salt" key_vault_id = azurerm_key_vault.keyvault.id - depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.current] + depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.CI] } data "azurerm_key_vault_secret" "strapi_app_keys" { name = "strapi-app-keys" key_vault_id = azurerm_key_vault.keyvault.id - depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.current] + depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.CI] } data "azurerm_key_vault_secret" "ilmo_auth_jwt_secret" { name = "ilmo-auth-jwt-secret" key_vault_id = azurerm_key_vault.keyvault.id - depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.current] + depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.CI] } data "azurerm_key_vault_secret" "ilmo_edit_token_secret" { name = "ilmo-edit-token-secret" key_vault_id = azurerm_key_vault.keyvault.id - depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.current] + depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.CI] } data "azurerm_key_vault_secret" "ilmo_mailgun_api_key" { name = "ilmo-mailgun-api-key" key_vault_id = azurerm_key_vault.keyvault.id - depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.current] + depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.CI] } data "azurerm_key_vault_secret" "ilmo_mailgun_domain" { name = "ilmo-mailgun-domain" key_vault_id = azurerm_key_vault.keyvault.id - depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.current] + depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.CI] } data "azurerm_key_vault_secret" "tikjob_ghost_mail_username" { name = "tikjob-ghost-mail-username" key_vault_id = azurerm_key_vault.keyvault.id - depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.current] + depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.CI] } data "azurerm_key_vault_secret" "tikjob_ghost_mail_password" { name = "tikjob-ghost-mail-password" key_vault_id = azurerm_key_vault.keyvault.id - depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.current] + depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.CI] } data "azurerm_key_vault_secret" "tenttiarkisto_django_secret_key" { name = "tenttiarkisto-django-secret-key" key_vault_id = azurerm_key_vault.keyvault.id - depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.current] + depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.CI] } data "azurerm_key_vault_secret" "github_app_key" { name = "github-app-key" key_vault_id = azurerm_key_vault.keyvault.id - depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.current] -} - -resource "azurerm_key_vault_secret" "postgres_admin_username" { - key_vault_id = azurerm_key_vault.keyvault.id - name = "postgres-admin-username" - value = var.tikweb_postgres_admin_username - depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.current] -} -resource "azurerm_key_vault_secret" "postgres_admin_password" { - key_vault_id = azurerm_key_vault.keyvault.id - name = "postgres-admin-password" - value = var.tikweb_postgres_admin_password - depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.current] + depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.CI] } diff --git a/modules/keyvault/output.tf b/modules/keyvault/output.tf index 4eeb89a..6741be6 100644 --- a/modules/keyvault/output.tf +++ b/modules/keyvault/output.tf @@ -44,9 +44,3 @@ output "tenttiarkisto_django_secret_key" { output "github_app_key" { value = data.azurerm_key_vault_secret.github_app_key.value } -output "tikweb_postgres_admin_password" { - value = azurerm_key_vault_secret.postgres_admin_password -} -output "tikweb_postgres_admin_username" { - value = azurerm_key_vault_secret.postgres_admin_username -}