Browse Source

Merge pull request #97 from mdr-engineering/feature/bp_MSOCI-1457_vault_stuff

Improves Vault Config
Brad Poulton 4 years ago
parent
commit
52c2411295
2 changed files with 4 additions and 2 deletions
  1. 1 1
      base/vault-configuration/main.tf
  2. 3 1
      base/vault-configuration/vars.tf

+ 1 - 1
base/vault-configuration/main.tf

@@ -69,7 +69,7 @@ resource "vault_jwt_auth_backend_role" "okta_oidc" {
   token_policies         = each.value.token_policies
   user_claim             = "email"
   role_type              = "oidc"
-  allowed_redirect_uris  = ["https://vault.pvt.xdrtest.accenturefederalcyber.com/ui/vault/auth/oidc/oidc/callback" ]
+  allowed_redirect_uris  = ["https://vault.${var.dns_info["private"]["zone"]}/ui/vault/auth/oidc/oidc/callback" ]
   oidc_scopes            = [ "profile", "email", "groups" ]
   bound_claims           = { groups = join(",", each.value.bound_groups) }
   verbose_oidc_logging   = false

+ 3 - 1
base/vault-configuration/vars.tf

@@ -32,4 +32,6 @@ variable "okta_oidc_client_secret" {
 variable "okta_api_token" {
   type        = string
   description = "Okta Vault api secret"
-}
+}
+
+variable "dns_info" { type = map }