- migrate from individual terraform files to config-driven terragrunt module structure - add vault_cluster module with config discovery system - replace individual .tf files with centralized config.hcl - restructure auth and secret backends as configurable modules - move auth roles and secret backends to yaml-based configuration - convert policies from .hcl to .yaml format, add rules/auth definition - add pre-commit hooks for yaml formatting and file cleanup - add terragrunt cache to gitignore - update makefile with terragrunt commands and format target
13 lines
281 B
YAML
13 lines
281 B
YAML
token_policies:
|
|
- "default_access"
|
|
- "kv/service/incus/incus-cluster-join-tokens"
|
|
token_ttl: 60
|
|
token_max_ttl: 120
|
|
bind_secret_id: false
|
|
token_bound_cidrs:
|
|
- "10.10.12.200/32"
|
|
- "198.18.13.77/32"
|
|
- "198.18.13.78/32"
|
|
- "198.18.13.79/32"
|
|
use_deterministic_role_id: false
|