- migrate from individual terraform files to config-driven terragrunt module structure - add vault_cluster module with config discovery system - replace individual .tf files with centralized config.hcl - restructure auth and secret backends as configurable modules - move auth roles and secret backends to yaml-based configuration - convert policies from .hcl to .yaml format, add rules/auth definition - add pre-commit hooks for yaml formatting and file cleanup - add terragrunt cache to gitignore - update makefile with terragrunt commands and format target
14 lines
325 B
YAML
14 lines
325 B
YAML
token_policies:
|
|
- "default_access"
|
|
- "kv/service/terraform/incus"
|
|
- "kv/service/puppet/certificates/terraform_puppet_cert"
|
|
token_ttl: 60
|
|
token_max_ttl: 120
|
|
bind_secret_id: false
|
|
token_bound_cidrs:
|
|
- "10.10.12.200/32"
|
|
- "198.18.25.102/32"
|
|
- "198.18.26.91/32"
|
|
- "198.18.27.40/32"
|
|
use_deterministic_role_id: false
|