Nothing stopped a policy under policies/x/y/ from granting a rule path outside its own directory, so an over-broad grant read as ordinary review noise and only surfaced once applied to Vault.
- add tests/test_policies.py: a pydantic model rejecting unknown keys, empty rules and non-Vault capabilities
- check every rule path segment-wise against the policy's own directory, stripping the kv-v2 data/metadata segment
- relocate the rules that reached outside their directory, carrying capabilities and auth bindings verbatim
- run the suite from a local pre-commit hook and from make test
Reviewed-on: #158
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
- migrate from individual terraform files to config-driven terragrunt module structure
- add vault_cluster module with config discovery system
- replace individual .tf files with centralized config.hcl
- restructure auth and secret backends as configurable modules
- move auth roles and secret backends to yaml-based configuration
- convert policies from .hcl to .yaml format, add rules/auth definition
- add pre-commit hooks for yaml formatting and file cleanup
- add terragrunt cache to gitignore
- update makefile with terragrunt commands and format target