3 Commits

Author SHA1 Message Date
unkin-agent 890d666a53 Keep policy rule paths within their own directory (#158)
ci/woodpecker/push/apply Pipeline was successful
Nothing stopped a policy under policies/x/y/ from granting a rule path outside its own directory, so an over-broad grant read as ordinary review noise and only surfaced once applied to Vault.

- add tests/test_policies.py: a pydantic model rejecting unknown keys, empty rules and non-Vault capabilities
- check every rule path segment-wise against the policy's own directory, stripping the kv-v2 data/metadata segment
- relocate the rules that reached outside their directory, carrying capabilities and auth bindings verbatim
- run the suite from a local pre-commit hook and from make test

Reviewed-on: #158
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-28 22:12:14 +10:00
unkinben 9cbac6d3ef feat: add plan workflow
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/plan Pipeline was successful
- update makefile to enable kubernetes auth or roleid auth
- add plan workflow
- update all policies to allow the terraform-vault kubernetes role
2026-05-21 23:52:30 +10:00
unkinben 8070b6f66b feat: major restructuring in migration to terragrunt
- migrate from individual terraform files to config-driven terragrunt module structure
- add vault_cluster module with config discovery system
- replace individual .tf files with centralized config.hcl
- restructure auth and secret backends as configurable modules
- move auth roles and secret backends to yaml-based configuration
- convert policies from .hcl to .yaml format, add rules/auth definition
- add pre-commit hooks for yaml formatting and file cleanup
- add terragrunt cache to gitignore
- update makefile with terragrunt commands and format target
2026-01-26 23:02:44 +11:00