-
Notifications
You must be signed in to change notification settings - Fork 540
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ldap rotation import skip parameter #2128
Changes from all commits
e61366f
ab89eaf
849cc8d
4621649
761ce2e
21c60df
3640082
cd1a8f9
a23c888
f5b287f
86cc396
8c28de0
7716303
abd73c2
6025d5e
19ee87b
2df416c
c8373b6
8864062
17274e4
cddd3b4
0574b4b
6cf7caf
9677686
080a09a
2e75933
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -39,6 +39,16 @@ func TestAccDataSourceLDAPStaticRoleCredentials(t *testing.T) { | |
resource.TestCheckResourceAttrSet(dataName, consts.FieldLastVaultRotation), | ||
), | ||
}, | ||
// second 1.16 gated check | ||
{ | ||
SkipFunc: func() (bool, error) { | ||
return !testProvider.Meta().(*provider.ProviderMeta).IsAPISupported(provider.VaultVersion116), nil | ||
}, | ||
Config: testLDAPStaticRoleDataSourceWithSkipImportRotation(backend, bindDN, bindPass, url, username, dn), | ||
Check: resource.ComposeTestCheckFunc( | ||
resource.TestCheckResourceAttr("vault_ldap_secret_backend_static_role_with_skip", consts.FieldSkipImportRotation, "true"), | ||
), | ||
}, | ||
Comment on lines
+42
to
+51
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. We should remove this since they are not relevant to the data source. |
||
}, | ||
}) | ||
} | ||
|
@@ -67,3 +77,29 @@ data "vault_ldap_static_credentials" "creds" { | |
} | ||
`, path, bindDN, bindPass, url, username, dn, username) | ||
} | ||
|
||
func testLDAPStaticRoleDataSourceWithSkipImportRotation(path, bindDN, bindPass, url, username, dn string) string { | ||
return fmt.Sprintf(` | ||
resource "vault_ldap_secret_backend" "test" { | ||
path = "%s" | ||
description = "test description" | ||
binddn = "%s" | ||
bindpass = "%s" | ||
url = "%s" | ||
} | ||
|
||
resource "vault_ldap_secret_backend_static_role_with_skip" "role" { | ||
mount = vault_ldap_secret_backend.test.path | ||
username = "%s" | ||
dn = "%s" | ||
role_name = "%s" | ||
rotation_period = 60 | ||
skip_import_rotation = true | ||
} | ||
|
||
data "vault_ldap_static_credentials" "creds" { | ||
mount = vault_ldap_secret_backend.test.path | ||
role_name = vault_ldap_secret_backend_static_role.role.role_name | ||
} | ||
`, path, bindDN, bindPass, url, username, dn, username) | ||
} | ||
Comment on lines
+80
to
+105
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. We should remove this since they are not relevant to the data source. |
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -72,3 +72,6 @@ In addition to the arguments above, the following attributes are exported: | |
* `ttl` - Duration in seconds after which the issued credential should expire. | ||
|
||
* `username` - The name of the static role. | ||
|
||
* `skip_import_rotation` - (Optional) Causes vault to skip the initial rotation on import. Not applicable on updates. | ||
Requires Vault 1.16 or above. | ||
Comment on lines
+75
to
+77
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. We should remove this since they are not relevant to the data source. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We should remove this since they are not relevant to the data source.