- manage python script/venv to sign ssh host certificates - add approle_id to puppetmaster eyaml files - add class to sign ssh-rsa host keys - add facts to check if the current principals match the desired principals
- changing vault url to vault.query.consul forced puppetmasters in drw1 to connect to syd1 vault hosts - set drw1 puppetmasters to use syd1 approle_id
- move vault certmanager tokens to drw1/syd1 specific eyaml - add syd1 certmanger token for syd1 vault