feat: major restructuring in migration to terragrunt
- migrate from individual terraform files to config-driven terragrunt module structure - add vault_cluster module with config discovery system - replace individual .tf files with centralized config.hcl - restructure auth and secret backends as configurable modules - move auth roles and secret backends to yaml-based configuration - convert policies from .hcl to .yaml format, add rules/auth definition - add pre-commit hooks for yaml formatting and file cleanup - add terragrunt cache to gitignore - update makefile with terragrunt commands and format target
This commit is contained in:
@@ -0,0 +1,17 @@
|
||||
backend: "pki/au/syd1"
|
||||
allow_ip_sans: true
|
||||
allowed_domains:
|
||||
- "unkin.net"
|
||||
- "*.unkin.net"
|
||||
- "localhost"
|
||||
allow_subdomains: true
|
||||
allow_glob_domains: true
|
||||
allow_bare_domains: true
|
||||
enforce_hostnames: true
|
||||
allow_any_name: true
|
||||
max_ttl: 7776000 # 2160 * 3600
|
||||
key_bits: 4096
|
||||
country:
|
||||
- "Australia"
|
||||
use_csr_common_name: true
|
||||
use_csr_sans: true
|
||||
@@ -0,0 +1,17 @@
|
||||
backend: "pki_int"
|
||||
allow_ip_sans: true
|
||||
allowed_domains:
|
||||
- "unkin.net"
|
||||
- "*.unkin.net"
|
||||
- "localhost"
|
||||
allow_subdomains: true
|
||||
allow_glob_domains: true
|
||||
allow_bare_domains: true
|
||||
enforce_hostnames: true
|
||||
allow_any_name: true
|
||||
max_ttl: 7776000 # 2160 * 3600
|
||||
key_bits: 4096
|
||||
country:
|
||||
- "Australia"
|
||||
use_csr_common_name: true
|
||||
use_csr_sans: true
|
||||
@@ -0,0 +1,15 @@
|
||||
backend: "pki_root"
|
||||
allow_ip_sans: true
|
||||
allowed_domains:
|
||||
- "unkin.net"
|
||||
- "unkin.local"
|
||||
allow_subdomains: true
|
||||
allow_glob_domains: false
|
||||
allow_bare_domains: true
|
||||
enforce_hostnames: false
|
||||
allow_any_name: false
|
||||
max_ttl: 31536000 # 8760h in seconds
|
||||
key_bits: 2048
|
||||
country: []
|
||||
use_csr_common_name: true
|
||||
use_csr_sans: true
|
||||
Reference in New Issue
Block a user