feat: major restructuring in migration to terragrunt
- migrate from individual terraform files to config-driven terragrunt module structure - add vault_cluster module with config discovery system - replace individual .tf files with centralized config.hcl - restructure auth and secret backends as configurable modules - move auth roles and secret backends to yaml-based configuration - convert policies from .hcl to .yaml format, add rules/auth definition - add pre-commit hooks for yaml formatting and file cleanup - add terragrunt cache to gitignore - update makefile with terragrunt commands and format target
This commit is contained in:
@@ -0,0 +1,11 @@
|
||||
bound_service_account_names:
|
||||
- ceph-csi-rbd-csi-rbd-provisioner
|
||||
- ceph-csi-cephfs-csi-cephfs-provisioner
|
||||
bound_service_account_namespaces:
|
||||
- csi-cephrbd
|
||||
- csi-cephfs
|
||||
token_ttl: 60
|
||||
token_policies:
|
||||
- kv/service/kubernetes/au/syd1/csi/ceph-rbd-secret/read
|
||||
- kv/service/kubernetes/au/syd1/csi/ceph-cephfs-secret/read
|
||||
audience: vault
|
||||
@@ -0,0 +1,9 @@
|
||||
bound_service_account_names:
|
||||
- cert-manager-vault-issuer
|
||||
bound_service_account_namespaces:
|
||||
- cert-manager
|
||||
token_ttl: 60
|
||||
token_policies:
|
||||
- pki_int/sign/servers_default
|
||||
- pki_int/issue/servers_default
|
||||
audience: vault
|
||||
@@ -0,0 +1,8 @@
|
||||
bound_service_account_names:
|
||||
- externaldns
|
||||
bound_service_account_namespaces:
|
||||
- externaldns
|
||||
token_ttl: 60
|
||||
token_policies:
|
||||
- kv/service/kubernetes/au/syd1/externaldns/tsig/read
|
||||
audience: vault
|
||||
@@ -0,0 +1,9 @@
|
||||
bound_service_account_names:
|
||||
- default
|
||||
bound_service_account_namespaces:
|
||||
- huntarr
|
||||
token_ttl: 60
|
||||
token_policies:
|
||||
- pki_int/sign/servers_default
|
||||
- pki_int/issue/servers_default
|
||||
audience: vault
|
||||
@@ -0,0 +1,9 @@
|
||||
bound_service_account_names:
|
||||
- media-apps-vault-reader
|
||||
bound_service_account_namespaces:
|
||||
- media-apps
|
||||
token_ttl: 60
|
||||
token_policies:
|
||||
- kv/service/media-apps/radarr/read
|
||||
- kv/service/media-apps/sonarr/read
|
||||
audience: vault
|
||||
@@ -0,0 +1,12 @@
|
||||
bound_service_account_names:
|
||||
- default
|
||||
bound_service_account_namespaces:
|
||||
- repoflow
|
||||
token_ttl: 60
|
||||
token_policies:
|
||||
- kv/service/repoflow/au/syd1/ceph-s3/read
|
||||
- kv/service/repoflow/au/syd1/elasticsearch/read
|
||||
- kv/service/repoflow/au/syd1/hasura/read
|
||||
- kv/service/repoflow/au/syd1/postgres/read
|
||||
- kv/service/repoflow/au/syd1/repoflow-server/read
|
||||
audience: vault
|
||||
Reference in New Issue
Block a user