ivan
8ee05e1dc6
++
Terraform Terragrunt (contour) / validate (push) Failing after 2s
Terraform Terragrunt (contour) / plan (push) Has been skipped
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-05 19:25:32 +05:00
ivan
cf347a6a1a
++
2026-08-05 19:11:51 +05:00
ivan
6421953c73
++
2026-08-05 16:40:24 +05:00
964c718dc8
++ add SKIP_POSTGRES_ADMIN/SKIP_KAFKA_ADMIN flags, mirroring SKIP_MINIO_ADMIN
Terraform Terragrunt (contour) / validate (push) Failing after 2s
Terraform Terragrunt (contour) / apply (push) Has been skipped
Terraform Terragrunt (contour) / plan (push) Has been skipped
2026-08-05 12:53:53 +03:00
7074281aba
++ add secrets-contract-probe test app for brusnika-stage acceptance test
2026-08-05 12:50:26 +03:00
9577ee8ad0
++ add verify_secret_contract.py for v2 secret acceptance testing
2026-08-05 12:43:30 +03:00
d645e43de5
++ add declarative secrets contract v2 (schema/ownership/targets/extra_fields)
...
module: optional schema/ownership/source_kind/source_ref/extra_fields fields,
backward compatible - legacy secrets keep resolving exactly as before.
ownership modes managed/referenced/observed/adopt_once replace ignore_changes
for v2 records; referenced reads a value straight from vault via a data
source; observed only verifies presence, writes nothing.
terragrunt: v1/v2 detection by marker keys, targets fan-out into the existing
flat secrets list (one entry per target, same resource-key scheme as today),
source.kind -> type/depends_on translation for the five documented kinds.
brusnika-stage: acceptance environment for the two test cases from the plan -
regcred (dockerconfigjson.v1, ownership=referenced, value from vault) and a
rabbitmq.v1 secret (ownership=managed) fanned out to both kubernetes and vault
targets from a single declaration.
2026-08-05 12:41:55 +03:00
8b98cee0a5
++ gitignore secrets contract plan
2026-08-05 12:02:03 +03:00
168f5d66ce
++ strip comments
2026-08-05 10:42:31 +03:00
b54fc6f29b
++ guard secrets/vault key typo at env top-level in contour terragrunt.hcl
2026-08-05 10:42:31 +03:00
ivan
631375d53f
++
2026-08-04 23:11:12 +05:00
1c232f7516
++ add dockerconfigjson contract check to k8s-secret module
2026-08-04 18:30:05 +03:00
9cde2dcab2
++ fail loudly on decrypt/env-lookup failure and secret key typos instead of silently empty
2026-08-04 18:30:05 +03:00
ivan
416efa8457
++
2026-08-04 19:08:28 +05:00
ivan
8991d27c7a
++
2026-08-04 18:40:29 +05:00
7a871a3577
++ fix namespace module comment grammar
2026-08-04 16:11:48 +03:00
61bd8a00f2
++ sync rabbitmq module with strict variable typing and password rotation guard
2026-08-04 16:06:31 +03:00
758226e29f
++ remove dead yc-only and unused k8s-secrets modules from contour
2026-08-04 15:26:24 +03:00
d08b3e1771
++ wrap all vault secret values under data key for selective sops encryption
2026-08-04 15:20:08 +03:00
284b235626
++ gitignore per-environment age private key docs
2026-08-04 13:58:26 +03:00
7c0e2dddfc
++ rename contour gitea secret to sops age key contour
2026-08-04 13:48:47 +03:00
12e406acad
++ fail secrets plan on incomplete depends_on instead of writing empty data
2026-08-04 13:19:54 +03:00
c7e04cb836
++ scope sops age key to decrypt step instead of whole ci job
2026-08-04 12:56:21 +03:00
854013a415
++ add contour-only age recipient to sops, keep old key for transition
2026-08-04 12:53:01 +03:00
ivan
545fa25abd
++
2026-08-04 12:29:42 +05:00
ivan
98750a048a
++
2026-08-03 16:36:40 +05:00
ivan
6510ed6386
++
2026-08-03 15:18:22 +05:00
0836a80800
++ persist camunda identity client secrets
2026-08-03 11:56:37 +03:00
ivan
0584257cd8
++
2026-08-02 01:09:44 +05:00
ivan
84091bcd25
++
2026-08-02 00:10:47 +05:00
ivan
0b65b58181
++
2026-08-01 17:37:50 +05:00
ivan
acdb4b6a91
++
2026-08-01 14:18:09 +05:00
ivan
3d69653667
++
2026-08-01 14:02:23 +05:00
ivan
f8ec3dac9f
++
2026-08-01 13:46:23 +05:00
ivan
27f0770e07
++
2026-08-01 13:06:59 +05:00
ivan
b0cf57d5eb
++
2026-07-31 18:40:41 +05:00
ivan
d5dcdf44f0
++
2026-07-31 17:12:51 +05:00
ivan
82e5014854
++
2026-07-31 15:04:18 +05:00
ivan
b818f612f0
++
2026-07-31 13:04:40 +05:00
ivan
f0b086a60f
++
2026-07-30 21:08:45 +05:00
ivan
644ea051a6
++
2026-07-29 18:23:55 +05:00
ivan
25228040a8
++
2026-07-29 18:21:01 +05:00
ivan
b3502feae4
++
2026-07-29 18:11:19 +05:00
ivan
b0f814e485
++
2026-07-29 17:31:10 +05:00
ivan
f64a59dd51
++
2026-07-29 14:58:02 +05:00
ivan
359aed4a7e
++
2026-07-29 14:31:12 +05:00
ivan
1741c5d4e8
++
2026-07-29 14:11:32 +05:00
ivan
8d785c7a46
++
2026-07-28 20:06:05 +05:00
ivan
194315a7fb
++
2026-07-28 19:59:41 +05:00
ivan
06e586090c
++
2026-07-28 19:50:36 +05:00