feat: major restructuring in migration to terragrunt

- migrate from individual terraform files to config-driven terragrunt module structure
- add vault_cluster module with config discovery system
- replace individual .tf files with centralized config.hcl
- restructure auth and secret backends as configurable modules
- move auth roles and secret backends to yaml-based configuration
- convert policies from .hcl to .yaml format, add rules/auth definition
- add pre-commit hooks for yaml formatting and file cleanup
- add terragrunt cache to gitignore
- update makefile with terragrunt commands and format target
This commit is contained in:
2026-01-04 23:31:42 +11:00
parent bd112181f5
commit 8070b6f66b
245 changed files with 3943 additions and 985 deletions
@@ -0,0 +1,11 @@
bound_service_account_names:
- ceph-csi-rbd-csi-rbd-provisioner
- ceph-csi-cephfs-csi-cephfs-provisioner
bound_service_account_namespaces:
- csi-cephrbd
- csi-cephfs
token_ttl: 60
token_policies:
- kv/service/kubernetes/au/syd1/csi/ceph-rbd-secret/read
- kv/service/kubernetes/au/syd1/csi/ceph-cephfs-secret/read
audience: vault
@@ -0,0 +1,9 @@
bound_service_account_names:
- cert-manager-vault-issuer
bound_service_account_namespaces:
- cert-manager
token_ttl: 60
token_policies:
- pki_int/sign/servers_default
- pki_int/issue/servers_default
audience: vault
@@ -0,0 +1,8 @@
bound_service_account_names:
- externaldns
bound_service_account_namespaces:
- externaldns
token_ttl: 60
token_policies:
- kv/service/kubernetes/au/syd1/externaldns/tsig/read
audience: vault
@@ -0,0 +1,9 @@
bound_service_account_names:
- default
bound_service_account_namespaces:
- huntarr
token_ttl: 60
token_policies:
- pki_int/sign/servers_default
- pki_int/issue/servers_default
audience: vault
@@ -0,0 +1,9 @@
bound_service_account_names:
- media-apps-vault-reader
bound_service_account_namespaces:
- media-apps
token_ttl: 60
token_policies:
- kv/service/media-apps/radarr/read
- kv/service/media-apps/sonarr/read
audience: vault
@@ -0,0 +1,12 @@
bound_service_account_names:
- default
bound_service_account_namespaces:
- repoflow
token_ttl: 60
token_policies:
- kv/service/repoflow/au/syd1/ceph-s3/read
- kv/service/repoflow/au/syd1/elasticsearch/read
- kv/service/repoflow/au/syd1/hasura/read
- kv/service/repoflow/au/syd1/postgres/read
- kv/service/repoflow/au/syd1/repoflow-server/read
audience: vault