Commit Graph

106 Commits

Author SHA1 Message Date
96ff8968e9 ++ compose keycloak-password into the policy-allowed camunda/postgresql secret 2026-08-26 14:17:25 +03:00
4b487e1fa0 ++ eliminate identity-password circular vault reference 2026-08-26 14:03:22 +03:00
e122f93749 ++ add missing camunda identity-components and identity-firstuser secrets 2026-08-26 13:51:44 +03:00
863c4896b0 ++ fix custom_keys misuse that overwrote real generated passwords 2026-08-26 13:44:22 +03:00
d2c2698765 ++ bind zitadel vault role to real service account name 2026-08-26 13:30:35 +03:00
17aede83c0 ++ drop circular keycloak-password ref from camunda-postgresql 2026-08-26 12:53:12 +03:00
d3b447e34c ++ fix camunda-postgresql secret to v2 contract shape 2026-08-26 12:45:49 +03:00
b578f442a7 ++ add regcred and protect existing infra secrets
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m0s
Terraform Terragrunt (contour) / plan (push) Successful in 1m5s
Terraform Terragrunt (contour) / apply (push) Successful in 1m3s
2026-08-26 12:32:46 +03:00
e28206025e ++ drop s3-proxy vault application 2026-08-26 12:20:56 +03:00
24de70dfa7 ++ add s3-proxy vault application for vad 2026-08-26 12:13:38 +03:00
5d0844b4c5 ++ wire zitadel and camunda vault secrets from real postgres passwords 2026-08-26 11:58:30 +03:00
917151ec16 ++ generate camunda and zitadel vault secrets for vad, drop conflicting db entries 2026-08-26 11:37:41 +03:00
715177b0a4 ++ add vad vault secrets stub 2026-08-25 20:03:37 +03:00
ivan
d5813ccd54 ++
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m22s
Terraform Terragrunt (contour) / plan (push) Successful in 1m31s
Terraform Terragrunt (contour) / apply (push) Successful in 1m39s
2026-08-21 14:30:35 +05:00
280559e7c8 ++ add superset trino ugmk secrets 2026-08-20 13:08:10 +03:00
128cdf0958 ++ drop test-terraform and rabbitmq-module-test from brusnika-stage
Some checks failed
Terraform Terragrunt (contour) / plan (push) Failing after 27s
Terraform Terragrunt (contour) / validate (push) Successful in 53s
Terraform Terragrunt (contour) / apply (push) Has been skipped
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 15:44:43 +03:00
ed3aaaed49 ++ vault creds and regcred for the shared rabbitmq on brusnika-stage
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 12:10:44 +03:00
ivan
962f748bf7 ++
Some checks failed
Terraform Terragrunt (contour) / validate (push) Failing after 4s
Terraform Terragrunt (contour) / plan (push) Has been skipped
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-12 13:14:52 +05:00
ivan
e8a0544ffc ++ wb: real postgres/rabbitmq/s3 creds, app vault roles, rsa_keys and minio infra from live cluster dump
Sourced from a kubectl dump of the wb cluster's k8s secrets, mirrored on
ugmk's vault paths where applicable. gitignore dumped-secrets/ working dir.
2026-08-12 12:50:13 +05:00
49164a6fde ++ strip trailing newline from wb regcred value 2026-08-11 16:25:46 +03:00
5b4b6084dd ++ drop wb kafka user and its secret, broker does not persist scram creds 2026-08-11 16:19:05 +03:00
f57f154d83 add kafka test topic/user to wb environment, wire kafka provider to work over TLS without SASL to match how production already connects to wb-prod-kafka-bootstrap:9093
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-11 14:15:57 +03:00
d5a2d639ad add wb environment, one test entity per resource type (namespace, rabbitmq vhost/user/queue, external postgres db/user, external minio bucket) plus matching v2 secret contracts
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-11 13:33:54 +03:00
ivan
d74baefa30 ++
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 53s
Terraform Terragrunt (contour) / plan (push) Successful in 55s
Terraform Terragrunt (contour) / apply (push) Successful in 55s
2026-08-09 14:16:10 +05:00
ivan
70895158fb ++ 2026-08-09 13:40:53 +05:00
ivan
0907728217 ++ 2026-08-09 13:18:23 +05:00
ivan
d03f2efba2 ++
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 52s
Terraform Terragrunt (contour) / plan (push) Successful in 54s
Terraform Terragrunt (contour) / apply (push) Successful in 59s
2026-08-08 16:01:03 +05:00
ivan
bb520d6980 ++
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 52s
Terraform Terragrunt (contour) / plan (push) Successful in 53s
Terraform Terragrunt (contour) / apply (push) Successful in 54s
2026-08-08 13:14:46 +05:00
ivan
46b6c5f74e ++ 2026-08-08 12:50:10 +05:00
94c4938547 align ugmk identity_components secrets with prod convention, connectors/operate/optimize/tasklist/zeebe now use the shared identity-secret-for-components value
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 52s
Terraform Terragrunt (contour) / plan (push) Successful in 54s
Terraform Terragrunt (contour) / apply (push) Successful in 56s
2026-08-07 16:49:17 +03:00
f9fca41c0c fix cde CAMUNDA_CLIENT_SECRET to match current zeebe-secret 2026-08-07 14:53:06 +03:00
261b581508 fix camunda vault secrets: restore admin/firstuser/db passwords as explicit values, add identity-password/keycloak-password fields to camunda_postgresql secret 2026-08-07 14:38:52 +03:00
cd14614538 ++ pilot external rabbitmq module on brusnika-stage only 2026-08-07 11:53:53 +03:00
ivan
b664a04688 ++
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 55s
Terraform Terragrunt (contour) / plan (push) Successful in 56s
Terraform Terragrunt (contour) / apply (push) Successful in 58s
2026-08-06 12:50:45 +05:00
ivan
bbe2b02e3c ++
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 56s
Terraform Terragrunt (contour) / plan (push) Successful in 57s
Terraform Terragrunt (contour) / apply (push) Successful in 58s
2026-08-06 12:27:25 +05:00
ivan
74f4e11b1d ++ 2026-08-05 19:59:52 +05:00
ivan
8ee05e1dc6 ++
Some checks failed
Terraform Terragrunt (contour) / validate (push) Failing after 2s
Terraform Terragrunt (contour) / plan (push) Has been skipped
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-05 19:25:32 +05:00
ivan
cf347a6a1a ++ 2026-08-05 19:11:51 +05:00
ivan
6421953c73 ++ 2026-08-05 16:40:24 +05:00
d645e43de5 ++ add declarative secrets contract v2 (schema/ownership/targets/extra_fields)
module: optional schema/ownership/source_kind/source_ref/extra_fields fields,
backward compatible - legacy secrets keep resolving exactly as before.
ownership modes managed/referenced/observed/adopt_once replace ignore_changes
for v2 records; referenced reads a value straight from vault via a data
source; observed only verifies presence, writes nothing.

terragrunt: v1/v2 detection by marker keys, targets fan-out into the existing
flat secrets list (one entry per target, same resource-key scheme as today),
source.kind -> type/depends_on translation for the five documented kinds.

brusnika-stage: acceptance environment for the two test cases from the plan -
regcred (dockerconfigjson.v1, ownership=referenced, value from vault) and a
rabbitmq.v1 secret (ownership=managed) fanned out to both kubernetes and vault
targets from a single declaration.
2026-08-05 12:41:55 +03:00
ivan
631375d53f ++ 2026-08-04 23:11:12 +05:00
ivan
416efa8457 ++ 2026-08-04 19:08:28 +05:00
ivan
8991d27c7a ++ 2026-08-04 18:40:29 +05:00
d08b3e1771 ++ wrap all vault secret values under data key for selective sops encryption 2026-08-04 15:20:08 +03:00
854013a415 ++ add contour-only age recipient to sops, keep old key for transition 2026-08-04 12:53:01 +03:00
ivan
545fa25abd ++ 2026-08-04 12:29:42 +05:00
ivan
98750a048a ++ 2026-08-03 16:36:40 +05:00
ivan
6510ed6386 ++ 2026-08-03 15:18:22 +05:00
0836a80800 ++ persist camunda identity client secrets 2026-08-03 11:56:37 +03:00
ivan
0584257cd8 ++ 2026-08-02 01:09:44 +05:00