certificates: restore the validly-signed intermediate in vault-ca-cert
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
This commit is contained in:
@@ -10,6 +10,11 @@ while IFS= read -r -d '' file; do
|
||||
|
||||
# Check if the file contains a plain Kubernetes Secret
|
||||
if grep -q "^kind: Secret" "$file"; then
|
||||
# Explicit opt-out for public-data bootstrap secrets (e.g. the CA bundle
|
||||
# that establishes Vault trust and therefore cannot be Vault-sourced).
|
||||
if grep -q "^# pre-commit: allow-plain-secret" "$file"; then
|
||||
continue
|
||||
fi
|
||||
# Allow secure secret types
|
||||
if ! grep -q -E "^kind: (SealedSecret|ExternalSecret|VaultStaticSecret|VaultDynamicSecret)" "$file"; then
|
||||
echo "BLOCKED: $file contains a plain Kubernetes Secret" >&2
|
||||
|
||||
Reference in New Issue
Block a user