73 Commits

Author SHA1 Message Date
jenkins
83f8d67640 feat(hermes): take the Anthropic credential from Vault
Some checks failed
Tests / Declarative: Post Actions testing.tests.test_repo_structure.test_knowledge_service_mirror_matches_source failed
The Claude subscription OAuth token was created as a manual kubectl Secret in
the interest of demo time, with migration to Vault agreed as follow-up. The
value now lives at kv/atlas/hermes/agent-tokens and is injected as a file.

The hermes role gains that path and binds the hermes-triage service account
the deployment actually runs as; it previously bound only hermes-vault. The
init container prefers the Vault file and falls back to the Secret, so this
can be rolled back by removing the annotations alone, and the Secret should be
deleted once Vault has been serving it for a while.

Vault was reachable all along without the operator credential: Ariadne already
holds a vault-admin Kubernetes auth role, which is how the value was written.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-06 12:14:52 -03:00
jenkins
ddb609dac7 ai(hermes): add isolated user chat instance 2026-08-02 02:31:01 -03:00
jenkins
25a194bf84 Preserve Cassandra legacy BYOK during cutover 2026-07-25 08:17:53 -03:00
jenkins
ea334a2863 feat(cassandra): add parallel migration infrastructure 2026-07-25 00:20:01 -03:00
jenkins
21798ca992 Deploy Cassandra 0.7.65 generator worker 2026-07-24 02:04:03 -03:00
jenkins
97ecb36b56 agent: replace OpenClaw with Hermes 2026-07-21 21:02:44 -03:00
jenkins
cf95e9ca07 vault: allow admin raft snapshots 2026-07-18 13:40:04 -03:00
jenkins
7dd6b6e066 vault: allow ui mount detail checks 2026-07-18 08:21:25 -03:00
jenkins
3431f1f58a Deploy Veles 0.4.1 runtime support 2026-06-27 19:07:16 -03:00
jenkins
a98e1bb7b2 gitea: wire Veles OIDC login 2026-06-20 14:08:18 -03:00
jenkins
654900b8a2 veles: stage atlas infrastructure 2026-06-09 00:46:46 -03:00
jenkins
1470cea862 game-stream: deploy Wolf foundation 2026-05-21 02:07:17 -03:00
jenkins
8ce8b1aac2 agent(openclaw): expose oauth protected UI 2026-05-20 17:22:12 -03:00
jenkins
9e659b790b recovery(post-outage): restore jellyfin and maintenance sync 2026-05-05 06:31:09 -03:00
jenkins
6c4a7dea29 recovery(metis): use atlas kv node secrets 2026-04-24 17:29:58 -03:00
jenkins
04a80c1168 recovery(metis): seed per-node vault password slots 2026-04-24 17:24:37 -03:00
7883593166 ci(jenkins): inject sonarqube token from vault 2026-04-21 19:43:08 -03:00
5bf01bb8e6 vault(auth): allow maintenance soteria oidc secret path 2026-04-12 17:23:41 -03:00
deb52c424b maintenance/vault: move Metis runtime secrets to Vault 2026-04-05 11:31:05 -03:00
0828f0cf9e maintenance: inject metis SSH keys directly from Vault 2026-04-05 10:31:20 -03:00
e84399d0b1 maintenance: source metis SSH keys from Vault 2026-04-05 10:25:29 -03:00
5ae6c5d4fb maintenance: remoteize metis build and flash 2026-03-31 20:42:35 -03:00
fdc80b9c0f sso: route metis through dedicated oauth2 proxy 2026-03-31 17:32:19 -03:00
00c0375790 comms: add synapse admin ensure job 2026-01-27 04:48:44 -03:00
6062e266aa vault: allow ariadne to use vault-admin role 2026-01-26 22:26:13 -03:00
096bb329e6 jenkins: sync harbor pull secret from vault 2026-01-22 04:45:24 -03:00
ee4af80e15 jenkins: use shared harbor creds when present 2026-01-22 03:15:38 -03:00
0ab34c0af5 ariadne: split portal and ariadne db secrets 2026-01-21 03:39:17 -03:00
0680926dae vault: allow ariadne to read needed secrets 2026-01-21 03:21:01 -03:00
587a0af1d7 maintenance: wire ariadne db and dashboards 2026-01-20 23:03:39 -03:00
a6b317097e fix: allow maintenance vault sync role 2026-01-19 19:07:00 -03:00
f3620aa2a4 chore: centralize harbor pull credentials 2026-01-19 19:02:14 -03:00
11a06e7683 feat: add Ariadne service and glue scheduling 2026-01-19 16:58:02 -03:00
47fdd97120 vault: allow vaultwarden mailu secret 2026-01-19 02:23:16 -03:00
e4a06c4ffb portal: use mailu smtp secret 2026-01-19 00:56:07 -03:00
cb5d38e979 vault: allow portal to read postmark relay 2026-01-18 01:17:52 -03:00
e0cc02d480 vault: make retry helper resilient 2026-01-17 03:09:33 -03:00
dfcf9bcc58 vault: retry vault cli operations 2026-01-17 03:00:25 -03:00
8f5efd3df9 vault: retry status checks in config jobs 2026-01-17 02:49:25 -03:00
15021dd2dc finance: seed vault secrets 2026-01-17 00:54:49 -03:00
05cdf75dc6 finance: add actual budget and firefly 2026-01-16 23:52:56 -03:00
5ba9501db9 longhorn: use harbor mirrors and vault pull secret 2026-01-16 17:31:29 -03:00
90a25ac73e platform: add cert-manager and align postgres vault path 2026-01-16 11:14:48 -03:00
a603b88eea vault/keycloak: restore kv access and wger sync rbac 2026-01-16 03:46:07 -03:00
b308ee8d55 vault: allow admin kv browse 2026-01-16 03:20:32 -03:00
05b0242e26 vault: allow UI mount listing for admins 2026-01-16 02:06:31 -03:00
d4f110534f vault: allow admin policy to update shared secrets 2026-01-15 04:17:14 -03:00
ebca451243 vault: allow sso role to read portal admin secret 2026-01-15 03:46:58 -03:00
ee1fd7f458 vault: default oidc claims type 2026-01-15 02:20:53 -03:00
d82146cfd6 vault: harden oidc claims type 2026-01-15 02:18:50 -03:00