2026-06-01 - 2026-09-01
Overview
69 Pull requests merged by 3 users
Merged
#149 Grant the vault deployer sudo to enable the oidc auth mount
Merged
#147 Add Authentik OIDC SSO as the default human login for OpenBao
Merged
#148 Grant the vault deployer auth/oidc and identity group capabilities
Merged
#146 Grant the vault deployer read on the Authentik OIDC client secret
Merged
#145 Bump vault-secrets-arrstack provider to 0.2.0 and plumb methods
Merged
#144 Bump arrstack plugin catalog to v0.2.0
Merged
#143 Grant terraform-rancher read on rancher/creds/ci
Merged
#141 Add arrstack creds role and k8s auth for mediamark
Merged
#142 Add ephemeral Gitea creds for repospawner
Merged
#140 Grant terraform-authentik write on the kv/service/authentik subtree
Merged
#139 Grant agents approle read on kv/service/authentik/agent-api-token
Merged
#138 Revert temporary agents read grant on Authentik provider token
Merged
#137 Grant agents AppRole read on the Authentik provider token
Merged
#136 Run plan without acquiring the Consul state lock
Merged
#135 operator RO creds: read operator CRD API groups
Merged
#134 Bump vault-secrets-arrstack provider to 0.1.1
Merged
#133 Sort arrstack role apps alphabetically
Merged
#132 Allow CSI auth to read ceph-mediafs-secret KV
Merged
#127 vault: mount arrstack engine + config + roles (3/3)
Merged
#131 Remove ghp agent role (missing installation_id; unblock apply)
Merged
#130 Restore ghp secret backend + roles (config now seeded)
Merged
#128 Grant agents approle write on ghp config KV path (to seed)
Merged
#126 vault: add arrstack policies (deployer + KV read + creds) (2/3)
Merged
#129 Temporarily remove ghp secret backend + roles (unblock apply)
Merged
#125 vault: register vault-plugin-secrets-arrstack in the catalog (1/3)
Merged
#121 vault: wire up ghp secrets engine (backend + role + policies)
Merged
#123 vault: register ghp plugin in the catalog (config/plugins only)
Merged
#122 vault: ghp engine config-write + consumer policies (apply before #121)
Merged
#119 Mint the netbox user-management credential dynamically from the single admin token
Merged
#117 Add the netbox backend and terraform-infra role
Merged
#115 Add the netbox secrets engine modules and wiring
Merged
#118 Register the netbox secrets plugin in the catalog
Merged
#116 Add netbox engine admin policy
Merged
#114 Let the agents AppRole mint unkin-agent Gitea tokens
Merged
#113 Grant terraform-infra kv metadata read
Merged
#111 Rename terraform-ipam CI Vault access -> terraform-infra
Merged
#110 Add terraform-ipam CI Vault access
Merged
#109 Add Vault-scoped agent kubernetes roles + agents AppRole
Merged
#106 Add logarchive gpg key + logging_logarchiver read access
Merged
#105 gitea roles: add read:user scope for API login validation
Merged
#101 gitea: add the gitea token secrets engine (mount, config, teabot roles)
Merged
#104 policies: allow terraform-git to delete the gitea config seed for taint recovery
Merged
#103 policies: grant terraform-git read on the gitea config KV metadata path
Merged
#102 policies: let terraform-git seed the gitea engine admin credential to KV
Merged
#100 policies: grant the vault deployer access to the gitea secrets engine
Merged
#99 ci: fetch vault from artifactapi instead of dnf install
Merged
#98 Add terraform-enc Vault/Consul plumbing + encapi token grant
Merged
#96 Bump rancher plugin catalog to v0.1.1 (bearerToken fix)
Merged
#93 Mount the rancher secrets engine + seed a service account + roles
Merged
#90 Manage the litellm plugin via config/plugins (import existing registration)
Merged
#92 Register the rancher plugin in the catalog (import)
Merged
#94 chore: setup access to enable all plugins, designated to tf-vault user
Merged
#91 Grant vault deployer access to import + manage the rancher engine
Merged
#87 Register + mount the GPG secrets engine at gpg/
Merged
#88 Grant vault deployer access to import + manage the gpg engine
Merged
#89 Add a plugin-import module + config/plugins for catalog registration
Merged
#86 Add auth and state access for terraform-rancher
Merged
#85 chore: update litellm address
Merged
#84 fix: grant vault deployer access to manage the litellm engine
Merged
#83 feat: manage litellm secrets engine via terraform-provider-litellmvaultsecret
Merged
#82 policies: let terraform-authentik read its provider API token
Merged
#81 policies: let terraform-authentik read oauth client secrets from kv
Merged
#79 feat: add vault/consul config for media terraform repos
Merged
#78 Add auth and state access for terraform-authentik
Merged
#77 feat: enable consul state store for artifactapi
Merged
#75 feat: add vault policy for terraform-git webhook secrets
Merged
#74 feat: manage gitadmin token
Merged
#73 feat: add vault and consul roles for terraform-git
Merged
#72 chore: bump almalinux9 image tags
2 Issues created by 1 user
Opened
#107 Harden seed modules: ignore_changes on rancher/litellm engine seed credentials
Opened
#112 terraform-vault plan CI broken: litellm secret backend returns 500 (blocks all PRs)