5b4b6084dd
++ drop wb kafka user and its secret, broker does not persist scram creds
2026-08-11 16:19:05 +03:00
f57f154d83
add kafka test topic/user to wb environment, wire kafka provider to work over TLS without SASL to match how production already connects to wb-prod-kafka-bootstrap:9093
...
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-11 14:15:57 +03:00
d5a2d639ad
add wb environment, one test entity per resource type (namespace, rabbitmq vhost/user/queue, external postgres db/user, external minio bucket) plus matching v2 secret contracts
...
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-11 13:33:54 +03:00
ivan
d74baefa30
++
Terraform Terragrunt (contour) / validate (push) Successful in 53s
Terraform Terragrunt (contour) / plan (push) Successful in 55s
Terraform Terragrunt (contour) / apply (push) Successful in 55s
2026-08-09 14:16:10 +05:00
ivan
70895158fb
++
2026-08-09 13:40:53 +05:00
ivan
0907728217
++
2026-08-09 13:18:23 +05:00
ivan
d03f2efba2
++
Terraform Terragrunt (contour) / validate (push) Successful in 52s
Terraform Terragrunt (contour) / plan (push) Successful in 54s
Terraform Terragrunt (contour) / apply (push) Successful in 59s
2026-08-08 16:01:03 +05:00
ivan
bb520d6980
++
Terraform Terragrunt (contour) / validate (push) Successful in 52s
Terraform Terragrunt (contour) / plan (push) Successful in 53s
Terraform Terragrunt (contour) / apply (push) Successful in 54s
2026-08-08 13:14:46 +05:00
ivan
46b6c5f74e
++
2026-08-08 12:50:10 +05:00
94c4938547
align ugmk identity_components secrets with prod convention, connectors/operate/optimize/tasklist/zeebe now use the shared identity-secret-for-components value
Terraform Terragrunt (contour) / validate (push) Successful in 52s
Terraform Terragrunt (contour) / plan (push) Successful in 54s
Terraform Terragrunt (contour) / apply (push) Successful in 56s
2026-08-07 16:49:17 +03:00
f9fca41c0c
fix cde CAMUNDA_CLIENT_SECRET to match current zeebe-secret
2026-08-07 14:53:06 +03:00
261b581508
fix camunda vault secrets: restore admin/firstuser/db passwords as explicit values, add identity-password/keycloak-password fields to camunda_postgresql secret
2026-08-07 14:38:52 +03:00
cd14614538
++ pilot external rabbitmq module on brusnika-stage only
2026-08-07 11:53:53 +03:00
ivan
b664a04688
++
Terraform Terragrunt (contour) / validate (push) Successful in 55s
Terraform Terragrunt (contour) / plan (push) Successful in 56s
Terraform Terragrunt (contour) / apply (push) Successful in 58s
2026-08-06 12:50:45 +05:00
ivan
bbe2b02e3c
++
Terraform Terragrunt (contour) / validate (push) Successful in 56s
Terraform Terragrunt (contour) / plan (push) Successful in 57s
Terraform Terragrunt (contour) / apply (push) Successful in 58s
2026-08-06 12:27:25 +05:00
ivan
74f4e11b1d
++
2026-08-05 19:59:52 +05:00
ivan
8ee05e1dc6
++
Terraform Terragrunt (contour) / validate (push) Failing after 2s
Terraform Terragrunt (contour) / plan (push) Has been skipped
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-05 19:25:32 +05:00
ivan
cf347a6a1a
++
2026-08-05 19:11:51 +05:00
ivan
6421953c73
++
2026-08-05 16:40:24 +05:00
d645e43de5
++ add declarative secrets contract v2 (schema/ownership/targets/extra_fields)
...
module: optional schema/ownership/source_kind/source_ref/extra_fields fields,
backward compatible - legacy secrets keep resolving exactly as before.
ownership modes managed/referenced/observed/adopt_once replace ignore_changes
for v2 records; referenced reads a value straight from vault via a data
source; observed only verifies presence, writes nothing.
terragrunt: v1/v2 detection by marker keys, targets fan-out into the existing
flat secrets list (one entry per target, same resource-key scheme as today),
source.kind -> type/depends_on translation for the five documented kinds.
brusnika-stage: acceptance environment for the two test cases from the plan -
regcred (dockerconfigjson.v1, ownership=referenced, value from vault) and a
rabbitmq.v1 secret (ownership=managed) fanned out to both kubernetes and vault
targets from a single declaration.
2026-08-05 12:41:55 +03:00
ivan
631375d53f
++
2026-08-04 23:11:12 +05:00
ivan
416efa8457
++
2026-08-04 19:08:28 +05:00
ivan
8991d27c7a
++
2026-08-04 18:40:29 +05:00
d08b3e1771
++ wrap all vault secret values under data key for selective sops encryption
2026-08-04 15:20:08 +03:00
854013a415
++ add contour-only age recipient to sops, keep old key for transition
2026-08-04 12:53:01 +03:00
ivan
545fa25abd
++
2026-08-04 12:29:42 +05:00
ivan
98750a048a
++
2026-08-03 16:36:40 +05:00
ivan
6510ed6386
++
2026-08-03 15:18:22 +05:00
0836a80800
++ persist camunda identity client secrets
2026-08-03 11:56:37 +03:00
ivan
0584257cd8
++
2026-08-02 01:09:44 +05:00
ivan
84091bcd25
++
2026-08-02 00:10:47 +05:00
ivan
0b65b58181
++
2026-08-01 17:37:50 +05:00
ivan
acdb4b6a91
++
2026-08-01 14:18:09 +05:00
ivan
3d69653667
++
2026-08-01 14:02:23 +05:00
ivan
f8ec3dac9f
++
2026-08-01 13:46:23 +05:00
ivan
27f0770e07
++
2026-08-01 13:06:59 +05:00
ivan
b0cf57d5eb
++
2026-07-31 18:40:41 +05:00
ivan
82e5014854
++
2026-07-31 15:04:18 +05:00
ivan
b818f612f0
++
2026-07-31 13:04:40 +05:00
ivan
f0b086a60f
++
2026-07-30 21:08:45 +05:00
ivan
644ea051a6
++
2026-07-29 18:23:55 +05:00
ivan
b3502feae4
++
2026-07-29 18:11:19 +05:00
ivan
b0f814e485
++
2026-07-29 17:31:10 +05:00
ivan
f64a59dd51
++
2026-07-29 14:58:02 +05:00
ivan
359aed4a7e
++
2026-07-29 14:31:12 +05:00
ivan
1741c5d4e8
++
2026-07-29 14:11:32 +05:00
ivan
8d785c7a46
++
2026-07-28 20:06:05 +05:00
ivan
194315a7fb
++
2026-07-28 19:59:41 +05:00
ivan
06e586090c
++
2026-07-28 19:50:36 +05:00
ivan
d38f1d2bf7
++
2026-07-28 19:40:17 +05:00