jenkins
83f8d67640
feat(hermes): take the Anthropic credential from Vault
...
Tests / Declarative: Post Actions testing.tests.test_repo_structure.test_knowledge_service_mirror_matches_source failed
The Claude subscription OAuth token was created as a manual kubectl Secret in
the interest of demo time, with migration to Vault agreed as follow-up. The
value now lives at kv/atlas/hermes/agent-tokens and is injected as a file.
The hermes role gains that path and binds the hermes-triage service account
the deployment actually runs as; it previously bound only hermes-vault. The
init container prefers the Vault file and falls back to the Secret, so this
can be rolled back by removing the annotations alone, and the Secret should be
deleted once Vault has been serving it for a while.
Vault was reachable all along without the operator credential: Ariadne already
holds a vault-admin Kubernetes auth role, which is how the value was written.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-06 12:14:52 -03:00
jenkins
ddb609dac7
ai(hermes): add isolated user chat instance
2026-08-02 02:31:01 -03:00
jenkins
25a194bf84
Preserve Cassandra legacy BYOK during cutover
2026-07-25 08:17:53 -03:00
jenkins
ea334a2863
feat(cassandra): add parallel migration infrastructure
2026-07-25 00:20:01 -03:00
jenkins
21798ca992
Deploy Cassandra 0.7.65 generator worker
2026-07-24 02:04:03 -03:00
jenkins
97ecb36b56
agent: replace OpenClaw with Hermes
2026-07-21 21:02:44 -03:00
jenkins
d701887bfe
vault: upgrade to 1.21.4
2026-07-18 14:04:08 -03:00
jenkins
5e1719fce0
vault: upgrade to 1.20.4
2026-07-18 13:58:22 -03:00
jenkins
5cad31bc24
vault: upgrade to 1.19.5
2026-07-18 13:51:27 -03:00
jenkins
9cbd7d1cf7
vault: upgrade to 1.18.5
2026-07-18 13:43:18 -03:00
jenkins
cf95e9ca07
vault: allow admin raft snapshots
2026-07-18 13:40:04 -03:00
jenkins
02ac19935a
vault: discourage public indexing
2026-07-18 11:38:42 -03:00
jenkins
d932c5b385
vault: tighten public response headers
2026-07-18 11:34:54 -03:00
jenkins
7dd6b6e066
vault: allow ui mount detail checks
2026-07-18 08:21:25 -03:00
jenkins
b1b23232b1
vault: keep ui api available
2026-07-18 08:19:50 -03:00
jenkins
f284291739
vault: harden public ingress
2026-07-18 03:34:17 -03:00
jenkins
3431f1f58a
Deploy Veles 0.4.1 runtime support
2026-06-27 19:07:16 -03:00
jenkins
a98e1bb7b2
gitea: wire Veles OIDC login
2026-06-20 14:08:18 -03:00
jenkins
654900b8a2
veles: stage atlas infrastructure
2026-06-09 00:46:46 -03:00
jenkins
1470cea862
game-stream: deploy Wolf foundation
2026-05-21 02:07:17 -03:00
jenkins
8ce8b1aac2
agent(openclaw): expose oauth protected UI
2026-05-20 17:22:12 -03:00
jenkins
69ff5b8bb2
vault: use http health probes
2026-05-19 17:25:56 -03:00
jenkins
9e659b790b
recovery(post-outage): restore jellyfin and maintenance sync
2026-05-05 06:31:09 -03:00
jenkins
6c4a7dea29
recovery(metis): use atlas kv node secrets
2026-04-24 17:29:58 -03:00
jenkins
04a80c1168
recovery(metis): seed per-node vault password slots
2026-04-24 17:24:37 -03:00
7883593166
ci(jenkins): inject sonarqube token from vault
2026-04-21 19:43:08 -03:00
5bf01bb8e6
vault(auth): allow maintenance soteria oidc secret path
2026-04-12 17:23:41 -03:00
deb52c424b
maintenance/vault: move Metis runtime secrets to Vault
2026-04-05 11:31:05 -03:00
0828f0cf9e
maintenance: inject metis SSH keys directly from Vault
2026-04-05 10:31:20 -03:00
e84399d0b1
maintenance: source metis SSH keys from Vault
2026-04-05 10:25:29 -03:00
5ae6c5d4fb
maintenance: remoteize metis build and flash
2026-03-31 20:42:35 -03:00
fdc80b9c0f
sso: route metis through dedicated oauth2 proxy
2026-03-31 17:32:19 -03:00
00c0375790
comms: add synapse admin ensure job
2026-01-27 04:48:44 -03:00
1b6fac86fb
vault: bootstrap k8s auth config with root token
2026-01-27 01:04:57 -03:00
6062e266aa
vault: allow ariadne to use vault-admin role
2026-01-26 22:26:13 -03:00
daf8be2d43
vault: unsuspend k8s auth config cronjob
2026-01-22 04:47:50 -03:00
096bb329e6
jenkins: sync harbor pull secret from vault
2026-01-22 04:45:24 -03:00
ee4af80e15
jenkins: use shared harbor creds when present
2026-01-22 03:15:38 -03:00
0ab34c0af5
ariadne: split portal and ariadne db secrets
2026-01-21 03:39:17 -03:00
0680926dae
vault: allow ariadne to read needed secrets
2026-01-21 03:21:01 -03:00
587a0af1d7
maintenance: wire ariadne db and dashboards
2026-01-20 23:03:39 -03:00
f8c368b21f
maintenance: extend Ariadne schedules and RBAC
2026-01-20 03:01:59 -03:00
a6b317097e
fix: allow maintenance vault sync role
2026-01-19 19:07:00 -03:00
f3620aa2a4
chore: centralize harbor pull credentials
2026-01-19 19:02:14 -03:00
11a06e7683
feat: add Ariadne service and glue scheduling
2026-01-19 16:58:02 -03:00
47fdd97120
vault: allow vaultwarden mailu secret
2026-01-19 02:23:16 -03:00
e4a06c4ffb
portal: use mailu smtp secret
2026-01-19 00:56:07 -03:00
84710b99e8
monitoring: add glue dashboard and tag cronjobs
2026-01-18 02:50:07 -03:00
cb5d38e979
vault: allow portal to read postmark relay
2026-01-18 01:17:52 -03:00
288f58e48c
vault: pin cronjobs to service IP
2026-01-17 03:17:36 -03:00