- migrate from individual terraform files to config-driven terragrunt module structure - add vault_cluster module with config discovery system - replace individual .tf files with centralized config.hcl - restructure auth and secret backends as configurable modules - move auth roles and secret backends to yaml-based configuration - convert policies from .hcl to .yaml format, add rules/auth definition - add pre-commit hooks for yaml formatting and file cleanup - add terragrunt cache to gitignore - update makefile with terragrunt commands and format target
13 lines
373 B
YAML
13 lines
373 B
YAML
bound_service_account_names:
|
|
- default
|
|
bound_service_account_namespaces:
|
|
- repoflow
|
|
token_ttl: 60
|
|
token_policies:
|
|
- kv/service/repoflow/au/syd1/ceph-s3/read
|
|
- kv/service/repoflow/au/syd1/elasticsearch/read
|
|
- kv/service/repoflow/au/syd1/hasura/read
|
|
- kv/service/repoflow/au/syd1/postgres/read
|
|
- kv/service/repoflow/au/syd1/repoflow-server/read
|
|
audience: vault
|