diff --git a/infra/ocp/connect/main.tf b/infra/ocp/connect/main.tf index f691087..4c53410 100644 --- a/infra/ocp/connect/main.tf +++ b/infra/ocp/connect/main.tf @@ -2,7 +2,12 @@ # Validates connectivity to an existing OpenShift cluster locals { - kubeconfig = var.kubeconfig_content != "" ? var.kubeconfig_content : yamlencode({ + # Precedence: forge-injected kubeconfig (registered cluster) > manual + # var.kubeconfig_content (standalone/override) > token-based fallback. + # local.forge_kubeconfig is injected by BNK-Forge via bnk_forge_locals.tf + # whenever this workspace has a registered cluster; try() falls through + # to the next tier when forge hasn't injected it (e.g. standalone runs). + kubeconfig = try(local.forge_kubeconfig, var.kubeconfig_content != "" ? var.kubeconfig_content : yamlencode({ apiVersion = "v1" kind = "Config" clusters = [{ name = "ocp", cluster = { @@ -12,7 +17,7 @@ locals { users = [{ name = "ocp-user", user = { token = var.oc_token } }] contexts = [{ name = "default", context = { cluster = "ocp", user = "ocp-user" } }] current-context = "default" - }) + })) } resource "local_file" "kubeconfig" { diff --git a/infra/ocp/connect/module.json b/infra/ocp/connect/module.json index 836fa2e..2639ec0 100644 --- a/infra/ocp/connect/module.json +++ b/infra/ocp/connect/module.json @@ -2,7 +2,7 @@ "module": { "name": "OpenShift Cluster Connection", "path": "infra/ocp/connect", - "version": "1.0.0", + "version": "1.0.1", "layer": "infrastructure", "category": "infra", "description": "Validates and connects to an existing OpenShift cluster", @@ -43,7 +43,7 @@ { "name": "kubeconfig_content", "type": "string", - "description": "Kubeconfig YAML content for the OCP cluster", + "description": "Kubeconfig YAML content for the OCP cluster. Automatically superseded by the project's registered-cluster kubeconfig when one exists; only used when no registered cluster is present, e.g. standalone or manual runs.", "default": "", "source": "project_secret" }, diff --git a/infra/ocp/connect/variables.tf b/infra/ocp/connect/variables.tf index fbf54f5..366eb68 100644 --- a/infra/ocp/connect/variables.tf +++ b/infra/ocp/connect/variables.tf @@ -9,7 +9,7 @@ variable "api_server_url" { } variable "kubeconfig_content" { - description = "Kubeconfig YAML content for the OCP cluster" + description = "Kubeconfig YAML content for the OCP cluster. Automatically superseded by the project's registered-cluster kubeconfig (local.forge_kubeconfig) when one exists; this variable is only used when no registered cluster is present, e.g. standalone or manual runs." type = string sensitive = true default = ""