Add Opensearch 1P service account token#208
Open
detjensrobert wants to merge 2 commits intolfit:mainfrom
Open
Conversation
This secret is originally from the Opensearch account Shared vault, but has been copied to the LF account Release Engineering vault so that it can be automatically rotated by the existing ESO. (This doesn't make sense to set up as its own second ESO store, since the cluster will not be fetching any other secrets from the Opensearch vault; the 1Password Jenkins plugin will be doing the fetching from the jobs which does not involve the cluster ESO) Signed-off-by: Robert Detjens <rdetjens@linuxfoundation.org>
The `op` cli is not used by the Jenkins controller and this token is only used by the JCASC to configure the plugin. The jobs that fetch 1P secrets get the token from the plugin config not this envvar. Signed-off-by: Robert Detjens <rdetjens@linuxfoundation.org>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This adds the 1Password service account token for the Opensearch account that is used to fetch job secrets via the 1Password Jenkins plugin. This only adds the envvar placement into the Jenkins and does not configure the 1P plugin in the JCASC.
Issue ref: https://jira.linuxfoundation.org/browse/IT-29070