2026-03-01 - 2026-09-01

Overview

81 Active Pull Requests
2 Active Issues
Excluding merges, 3 authors have pushed 71 commits to master and 96 commits to all branches. On master, 215 files have changed and there have been 4304 additions and 147 deletions.

81 Pull requests merged by 3 users

Merged #149 Grant the vault deployer sudo to enable the oidc auth mount 2026-08-31 22:21:02 +10:00

Merged #147 Add Authentik OIDC SSO as the default human login for OpenBao 2026-08-30 22:38:05 +10:00

Merged #148 Grant the vault deployer auth/oidc and identity group capabilities 2026-08-30 22:14:43 +10:00

Merged #146 Grant the vault deployer read on the Authentik OIDC client secret 2026-08-30 21:50:58 +10:00

Merged #145 Bump vault-secrets-arrstack provider to 0.2.0 and plumb methods 2026-08-30 18:19:05 +10:00

Merged #144 Bump arrstack plugin catalog to v0.2.0 2026-08-30 17:07:29 +10:00

Merged #143 Grant terraform-rancher read on rancher/creds/ci 2026-08-30 09:42:00 +10:00

Merged #141 Add arrstack creds role and k8s auth for mediamark 2026-08-30 09:40:27 +10:00

Merged #142 Add ephemeral Gitea creds for repospawner 2026-08-30 09:29:26 +10:00

Merged #140 Grant terraform-authentik write on the kv/service/authentik subtree 2026-08-29 23:01:43 +10:00

Merged #139 Grant agents approle read on kv/service/authentik/agent-api-token 2026-08-29 12:56:07 +10:00

Merged #138 Revert temporary agents read grant on Authentik provider token 2026-08-25 21:35:57 +10:00

Merged #137 Grant agents AppRole read on the Authentik provider token 2026-08-23 22:34:32 +10:00

Merged #136 Run plan without acquiring the Consul state lock 2026-08-23 22:31:58 +10:00

Merged #135 operator RO creds: read operator CRD API groups 2026-08-23 12:29:02 +10:00

Merged #134 Bump vault-secrets-arrstack provider to 0.1.1 2026-08-23 11:30:21 +10:00

Merged #133 Sort arrstack role apps alphabetically 2026-08-22 23:25:44 +10:00

Merged #132 Allow CSI auth to read ceph-mediafs-secret KV 2026-08-22 23:17:18 +10:00

Merged #127 vault: mount arrstack engine + config + roles (3/3) 2026-08-21 00:09:47 +10:00

Merged #131 Remove ghp agent role (missing installation_id; unblock apply) 2026-08-20 00:05:14 +10:00

Merged #130 Restore ghp secret backend + roles (config now seeded) 2026-08-19 23:47:32 +10:00

Merged #128 Grant agents approle write on ghp config KV path (to seed) 2026-08-19 23:17:45 +10:00

Merged #126 vault: add arrstack policies (deployer + KV read + creds) (2/3) 2026-08-19 22:54:14 +10:00

Merged #129 Temporarily remove ghp secret backend + roles (unblock apply) 2026-08-19 22:51:55 +10:00

Merged #125 vault: register vault-plugin-secrets-arrstack in the catalog (1/3) 2026-08-19 21:50:56 +10:00

Merged #121 vault: wire up ghp secrets engine (backend + role + policies) 2026-08-16 15:55:01 +10:00

Merged #123 vault: register ghp plugin in the catalog (config/plugins only) 2026-08-16 15:43:18 +10:00

Merged #122 vault: ghp engine config-write + consumer policies (apply before #121) 2026-08-16 14:49:35 +10:00

Merged #119 Mint the netbox user-management credential dynamically from the single admin token 2026-08-12 00:03:13 +10:00

Merged #117 Add the netbox backend and terraform-infra role 2026-08-11 20:43:05 +10:00

Merged #115 Add the netbox secrets engine modules and wiring 2026-08-09 16:36:18 +10:00

Merged #118 Register the netbox secrets plugin in the catalog 2026-08-09 16:30:07 +10:00

Merged #116 Add netbox engine admin policy 2026-08-09 12:02:13 +10:00

Merged #114 Let the agents AppRole mint unkin-agent Gitea tokens 2026-08-08 23:41:54 +10:00

Merged #113 Grant terraform-infra kv metadata read 2026-08-06 23:17:35 +10:00

Merged #111 Rename terraform-ipam CI Vault access -> terraform-infra 2026-08-06 22:25:39 +10:00

Merged #110 Add terraform-ipam CI Vault access 2026-08-03 00:16:35 +10:00

Merged #109 Add Vault-scoped agent kubernetes roles + agents AppRole 2026-08-02 21:55:06 +10:00

Merged #106 Add logarchive gpg key + logging_logarchiver read access 2026-07-29 20:39:41 +10:00

Merged #105 gitea roles: add read:user scope for API login validation 2026-07-28 18:07:29 +10:00

Merged #101 gitea: add the gitea token secrets engine (mount, config, teabot roles) 2026-07-27 23:42:13 +10:00

Merged #104 policies: allow terraform-git to delete the gitea config seed for taint recovery 2026-07-27 23:36:54 +10:00

Merged #103 policies: grant terraform-git read on the gitea config KV metadata path 2026-07-27 23:21:44 +10:00

Merged #102 policies: let terraform-git seed the gitea engine admin credential to KV 2026-07-27 20:22:41 +10:00

Merged #100 policies: grant the vault deployer access to the gitea secrets engine 2026-07-27 19:10:22 +10:00

Merged #99 ci: fetch vault from artifactapi instead of dnf install 2026-07-25 09:47:35 +10:00

Merged #98 Add terraform-enc Vault/Consul plumbing + encapi token grant 2026-07-24 23:18:56 +10:00

Merged #96 Bump rancher plugin catalog to v0.1.1 (bearerToken fix) 2026-07-18 22:59:36 +10:00

Merged #93 Mount the rancher secrets engine + seed a service account + roles 2026-07-18 16:16:54 +10:00

Merged #90 Manage the litellm plugin via config/plugins (import existing registration) 2026-07-18 14:55:34 +10:00

Merged #92 Register the rancher plugin in the catalog (import) 2026-07-18 14:47:08 +10:00

Merged #94 chore: setup access to enable all plugins, designated to tf-vault user 2026-07-18 14:42:02 +10:00

Merged #91 Grant vault deployer access to import + manage the rancher engine 2026-07-18 14:34:54 +10:00

Merged #87 Register + mount the GPG secrets engine at gpg/ 2026-07-17 23:19:38 +10:00

Merged #88 Grant vault deployer access to import + manage the gpg engine 2026-07-17 23:09:31 +10:00

Merged #89 Add a plugin-import module + config/plugins for catalog registration 2026-07-17 23:08:05 +10:00

Merged #86 Add auth and state access for terraform-rancher 2026-07-15 21:37:46 +10:00

Merged #85 chore: update litellm address 2026-07-09 23:47:33 +10:00

Merged #84 fix: grant vault deployer access to manage the litellm engine 2026-07-07 20:10:43 +10:00

Merged #83 feat: manage litellm secrets engine via terraform-provider-litellmvaultsecret 2026-07-07 00:18:29 +10:00

Merged #82 policies: let terraform-authentik read its provider API token 2026-07-06 23:41:03 +10:00

Merged #81 policies: let terraform-authentik read oauth client secrets from kv 2026-07-06 23:05:21 +10:00

Merged #79 feat: add vault/consul config for media terraform repos 2026-06-28 22:03:26 +10:00

Merged #78 Add auth and state access for terraform-authentik 2026-06-28 01:17:51 +10:00

Merged #77 feat: enable consul state store for artifactapi 2026-06-17 21:42:26 +10:00

Merged #75 feat: add vault policy for terraform-git webhook secrets 2026-06-08 22:56:30 +10:00

Merged #74 feat: manage gitadmin token 2026-06-08 15:17:59 +10:00

Merged #73 feat: add vault and consul roles for terraform-git 2026-06-07 20:36:35 +10:00

Merged #72 chore: bump almalinux9 image tags 2026-06-07 00:35:31 +10:00

Merged #71 fix: apply requires plan 2026-05-22 00:03:09 +10:00

Merged #70 feat: add apply workflow 2026-05-21 23:57:26 +10:00

Merged #69 feat: add plan workflow 2026-05-21 23:54:08 +10:00

Merged #68 chore: enable access to gateway.networking.k8s.io 2026-05-21 22:42:28 +10:00

Merged #67 chore: change to specific ci image 2026-03-09 01:17:00 +11:00

Merged #66 feat: add templated policies for kubernetes 2026-03-08 12:57:59 +11:00

Merged #65 fix: update audience for rpmbuilder 2026-03-08 12:29:43 +11:00

Merged #64 feat: add rpmbuilder k8s role 2026-03-07 11:11:24 +11:00

Merged #63 feat: enable woodpecker access to ro tokens 2026-03-07 10:52:39 +11:00

Merged #62 chore: move pgsql password to vault 2026-03-06 19:51:25 +11:00

Merged #61 chore: add artifactapi k8s role 2026-03-06 18:57:09 +11:00

Merged #60 chore: enable access woodpecker-agent-secret 2026-03-03 23:34:32 +11:00

2 Issues created by 1 user