Files
terraform-vault/.pre-commit-config.yaml
T
unkin-agent 890d666a53
ci/woodpecker/push/apply Pipeline was successful
Keep policy rule paths within their own directory (#158)
Nothing stopped a policy under policies/x/y/ from granting a rule path outside its own directory, so an over-broad grant read as ordinary review noise and only surfaced once applied to Vault.

- add tests/test_policies.py: a pydantic model rejecting unknown keys, empty rules and non-Vault capabilities
- check every rule path segment-wise against the policy's own directory, stripping the kv-v2 data/metadata segment
- relocate the rules that reached outside their directory, carrying capabilities and auth bindings verbatim
- run the suite from a local pre-commit hook and from make test

Reviewed-on: #158
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-28 22:12:14 +10:00

34 lines
922 B
YAML

repos:
- repo: https://github.com/pre-commit/pre-commit-hooks
rev: v4.4.0
hooks:
- id: end-of-file-fixer
types: [yaml]
- id: trailing-whitespace
types: [yaml]
- repo: https://github.com/gruntwork-io/pre-commit
rev: v0.1.30
hooks:
- id: tofu-fmt
- id: tofu-validate
- id: tflint
- id: terragrunt-hcl-fmt
- repo: https://github.com/adrienverge/yamllint.git
rev: v1.37.1
hooks:
- id: yamllint
args:
[
"-d {extends: relaxed, rules: {line-length: disable}, ignore: chart}",
"-s",
]
- repo: local
hooks:
- id: vault-yaml-tests
name: vault yaml definitions pass their unit tests
entry: python3 -m unittest discover -s tests -t .
language: python
additional_dependencies: [pyyaml, pydantic]
pass_filenames: false
always_run: true