# Mounts the arrstack dynamic secrets engine at "arrstack" and writes its config. # The arrproxy admin token is sensitive and read from KV, not stored here: # kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token -> key "token" # (seeded by argocd-apps #384). arrstack.unkin.net terminates on traefik-external # with an internal-CA cert the OpenBao nodes already trust, so ca_cert is omitted # (system trust store), mirroring the gitea engine against git.unkin.net. description: "arrstack dynamic arrproxy API keys" base_url: "https://arrstack.unkin.net" request_timeout_seconds: 30