feat: major restructuring in migration to terragrunt

- migrate from individual terraform files to config-driven terragrunt module structure
- add vault_cluster module with config discovery system
- replace individual .tf files with centralized config.hcl
- restructure auth and secret backends as configurable modules
- move auth roles and secret backends to yaml-based configuration
- convert policies from .hcl to .yaml format, add rules/auth definition
- add pre-commit hooks for yaml formatting and file cleanup
- add terragrunt cache to gitignore
- update makefile with terragrunt commands and format target
This commit is contained in:
2026-01-04 23:31:42 +11:00
parent bd112181f5
commit 8070b6f66b
245 changed files with 3943 additions and 985 deletions
@@ -0,0 +1,17 @@
backend: "pki/au/syd1"
allow_ip_sans: true
allowed_domains:
- "unkin.net"
- "*.unkin.net"
- "localhost"
allow_subdomains: true
allow_glob_domains: true
allow_bare_domains: true
enforce_hostnames: true
allow_any_name: true
max_ttl: 7776000 # 2160 * 3600
key_bits: 4096
country:
- "Australia"
use_csr_common_name: true
use_csr_sans: true
@@ -0,0 +1,17 @@
backend: "pki_int"
allow_ip_sans: true
allowed_domains:
- "unkin.net"
- "*.unkin.net"
- "localhost"
allow_subdomains: true
allow_glob_domains: true
allow_bare_domains: true
enforce_hostnames: true
allow_any_name: true
max_ttl: 7776000 # 2160 * 3600
key_bits: 4096
country:
- "Australia"
use_csr_common_name: true
use_csr_sans: true
@@ -0,0 +1,15 @@
backend: "pki_root"
allow_ip_sans: true
allowed_domains:
- "unkin.net"
- "unkin.local"
allow_subdomains: true
allow_glob_domains: false
allow_bare_domains: true
enforce_hostnames: false
allow_any_name: false
max_ttl: 31536000 # 8760h in seconds
key_bits: 2048
country: []
use_csr_common_name: true
use_csr_sans: true