890d666a53
ci/woodpecker/push/apply Pipeline was successful
Nothing stopped a policy under policies/x/y/ from granting a rule path outside its own directory, so an over-broad grant read as ordinary review noise and only surfaced once applied to Vault. - add tests/test_policies.py: a pydantic model rejecting unknown keys, empty rules and non-Vault capabilities - check every rule path segment-wise against the policy's own directory, stripping the kv-v2 data/metadata segment - relocate the rules that reached outside their directory, carrying capabilities and auth bindings verbatim - run the suite from a local pre-commit hook and from make test Reviewed-on: #158 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
34 lines
922 B
YAML
34 lines
922 B
YAML
repos:
|
|
- repo: https://github.com/pre-commit/pre-commit-hooks
|
|
rev: v4.4.0
|
|
hooks:
|
|
- id: end-of-file-fixer
|
|
types: [yaml]
|
|
- id: trailing-whitespace
|
|
types: [yaml]
|
|
- repo: https://github.com/gruntwork-io/pre-commit
|
|
rev: v0.1.30
|
|
hooks:
|
|
- id: tofu-fmt
|
|
- id: tofu-validate
|
|
- id: tflint
|
|
- id: terragrunt-hcl-fmt
|
|
- repo: https://github.com/adrienverge/yamllint.git
|
|
rev: v1.37.1
|
|
hooks:
|
|
- id: yamllint
|
|
args:
|
|
[
|
|
"-d {extends: relaxed, rules: {line-length: disable}, ignore: chart}",
|
|
"-s",
|
|
]
|
|
- repo: local
|
|
hooks:
|
|
- id: vault-yaml-tests
|
|
name: vault yaml definitions pass their unit tests
|
|
entry: python3 -m unittest discover -s tests -t .
|
|
language: python
|
|
additional_dependencies: [pyyaml, pydantic]
|
|
pass_filenames: false
|
|
always_run: true
|