Skip to content

ci: remove VAULT_ADDR override, fix stale create_key comment - #19

Closed
jbachorik wants to merge 1 commit into
mainfrom
jb/fix-vault-addr
Closed

jbachorik wants to merge 1 commit into
mainfrom
jb/fix-vault-addr

Conversation

@jbachorik

Copy link
Copy Markdown
Collaborator

What does this PR do?

Removes the global VAULT_ADDR variable from .gitlab-ci.yml and replaces it with an explanatory comment.
Also corrects a stale comment on the create_key job that still referenced AWS SSM.

Motivation

The CI secrets documentation explicitly warns:

When reading Vault secrets from a GitLab CI job using the Vault CLI or Vault SDK, be careful to not set the VAULT_ADDR environment variable. A VAULT_ADDR environment variable is already injected in the environment of your CI job, and overwriting it will cause clients to skip Emissary and not have a vault token attached to their request, causing requests to fail.

The global VAULT_ADDR: "https://vault.us1.ddbuild.io" was bypassing Emissary and would prevent the vault kv get calls in publish_snapshot and publish_to_maven_central from authenticating.

Companion to DataDog/vault-config#9548 (admin Vault policy for java-reggie CI secrets).

Related Issue(s)

DataDog/vault-config#9548

Change Type

  • Bug fix
  • New feature
  • Performance improvement
  • Refactoring (no functional change)
  • Documentation
  • Test improvement
  • Build/CI change

Checklist

  • I have read the CONTRIBUTING.md guidelines
  • All existing tests pass (./gradlew build)
  • I have added tests for my changes
  • I have updated documentation (if applicable)
  • My commits are signed

Performance Impact

N/A

Additional Notes

The update-maven-central-secrets.sh local script is unaffected — it uses ${VAULT_ADDR:-https://vault.us1.ddbuild.io} with a safe fallback that does not override a pre-existing value.

🤖 Generated with Claude Code

Emissary injects VAULT_ADDR in CI; setting it globally bypasses
Emissary and drops the vault token, breaking auth.

Also corrects stale comment in create_key: key is stored in Vault
at kv/k8s/gitlab-runner/java-reggie/signing, not AWS SSM.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@jbachorik jbachorik added the AI Generated or assisted by AI label Apr 16, 2026
@jbachorik jbachorik closed this May 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

AI Generated or assisted by AI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant