Files
project-gitops/infrastructure/live/dev-k3s/vault-foundation
2026-08-28 17:24:26 +09:00
..
2026-08-28 17:24:26 +09:00
2026-08-28 17:24:26 +09:00
2026-08-28 17:24:26 +09:00
2026-08-28 17:24:26 +09:00
2026-08-28 17:24:26 +09:00
2026-08-28 17:24:26 +09:00

dev-k3s Vault foundation

대상과 State

  • Environment/cluster: dev-k3s
  • Provider: HashiCorp Vault
  • State: vault-foundation
  • Backend example: backend.s3.hcl.example
  • Owner: bootstrap/security administrator

Vault mount, Kubernetes auth config, delegated automation policy와 선택적 CI JWT role을 소유합니다. Routine automation 대상이 아니며 downstream state가 자기 실행 권한을 직접 만들지 않도록 합니다.

policies/는 이 state가 소유하는 정확한 delegated automation ACL입니다. 실행과 복구 절차는 docs/runbooks/dev-bootstrap.mddocs/runbooks/terraform-state-migration.md를 따릅니다.