- migrate from individual terraform files to config-driven terragrunt module structure - add vault_cluster module with config discovery system - replace individual .tf files with centralized config.hcl - restructure auth and secret backends as configurable modules - move auth roles and secret backends to yaml-based configuration - convert policies from .hcl to .yaml format, add rules/auth definition - add pre-commit hooks for yaml formatting and file cleanup - add terragrunt cache to gitignore - update makefile with terragrunt commands and format target
15 lines
305 B
YAML
15 lines
305 B
YAML
token_policies:
|
|
- "ssh-host-signer/sshsigner"
|
|
- "sshca_signhost"
|
|
token_ttl: 30
|
|
token_max_ttl: 30
|
|
bind_secret_id: false
|
|
token_bound_cidrs:
|
|
- "198.18.25.5/32"
|
|
- "198.18.26.3/32"
|
|
- "198.18.27.89/32"
|
|
- "198.18.28.8/32"
|
|
- "198.18.29.33/32"
|
|
- "198.18.29.239/32"
|
|
use_deterministic_role_id: false
|