1243 Commits

Author SHA1 Message Date
be9d4bf32e comms: shorten vault inject file names 2026-01-14 14:21:58 -03:00
f11fb2e2e1 vault: move comms and mailu workloads to injector 2026-01-14 14:17:26 -03:00
f126dc5412 keycloak: schedule on arm64 workers 2026-01-14 13:49:37 -03:00
558c1a0b32 gitea: tolerate oidc init failures 2026-01-14 13:46:34 -03:00
6d46ca1e3b gitea: trim vault secret newlines 2026-01-14 13:43:56 -03:00
65d87f0b2e keycloak: bump job names 2026-01-14 13:42:08 -03:00
4279db1619 vault: stabilize injector templates and add health apps 2026-01-14 13:40:29 -03:00
1c3cb83b0a keycloak: switch jobs to vault injector 2026-01-14 13:20:57 -03:00
50b446aec3 nextcloud: fix vault template keys 2026-01-14 13:00:21 -03:00
3c5032f12f gitea: run vault init first 2026-01-14 12:44:49 -03:00
0928c62d91 bstein-dev-home: bump onboarding job 2026-01-14 12:34:02 -03:00
9c99e68ad8 vault: move core apps to injector 2026-01-14 12:28:10 -03:00
ac0d7a40ab infra: add vault injector 2026-01-14 11:46:13 -03:00
c9483b2d80 vault: sync harbor pulls 2026-01-14 10:07:31 -03:00
e897858d97 monitoring: move grafana smtp to vault 2026-01-14 06:41:34 -03:00
c24c7284e5 vault: add remaining secret syncs 2026-01-14 06:16:42 -03:00
c0bab2d528 jobs: bump names after vault tweaks 2026-01-14 05:47:21 -03:00
ab51d54101 jobs: drop apk in kubectl image 2026-01-14 05:41:01 -03:00
8b01bed322 comms: restore livekit token env 2026-01-14 05:35:51 -03:00
a4ecb0f2aa jobs: bump names for immutability 2026-01-14 05:32:07 -03:00
48b81d0b22 mailu: bump sync job name 2026-01-14 05:11:27 -03:00
bdc32b7a36 vault(consumption): sync secrets via CSI 2026-01-14 05:07:23 -03:00
58a9eb8a35 vault: send oidc role payload as json 2026-01-14 03:45:03 -03:00
13583a9a87 fix(gitea): inline vault secrets 2026-01-14 03:11:53 -03:00
306ed18c80 fix: resolve gitea mounts and bump portal job 2026-01-14 03:00:10 -03:00
3bcf04f754 vault: write bound_claims as file 2026-01-14 02:56:29 -03:00
3c65695dfc vault: wire more services to CSI 2026-01-14 02:54:59 -03:00
7d884b2bc8 vault: fix oidc scopes parsing 2026-01-14 02:52:51 -03:00
ca0c618f82 vault: run oidc config with sh 2026-01-14 02:28:38 -03:00
0d9291da7e vault: align oidc roles with keycloak 2026-01-14 02:24:32 -03:00
8567cfbee2 fix: detect vault initialized state correctly 2026-01-14 01:42:28 -03:00
ed7ff3b810 fix: make vault k8s auth script posix 2026-01-14 01:38:27 -03:00
c096b35078 fix: run vault k8s auth config with sh 2026-01-14 01:35:06 -03:00
5d53d900aa feat: start vault consumption for outline and planka 2026-01-14 01:30:41 -03:00
023032fd76 keycloak: fix harbor oidc job 2026-01-14 01:24:18 -03:00
f343f58ced keycloak: bump harbor oidc job 2026-01-14 01:22:30 -03:00
6779e99617 keycloak: ensure harbor oidc scope 2026-01-14 01:21:08 -03:00
ff29339a19 chore: refresh knowledge catalog headers 2026-01-14 01:08:05 -03:00
ac1389b75b feat: add harbor/vault oidc automation 2026-01-14 01:07:47 -03:00
c2aef63e95 monitoring: allow grafana upgrade remediation 2026-01-13 21:18:42 -03:00
4daa5f0e50 monitoring: align victoria-metrics PVC size 2026-01-13 21:15:10 -03:00
b70d9a6328 comms: restart atlasbot after MAS fixes 2026-01-13 21:09:41 -03:00
49c4cdb10c comms: rerun mas local user seed 2026-01-13 21:06:45 -03:00
08a6b7e118 comms: disable synapse oidc with MAS 2026-01-13 21:04:29 -03:00
1bbafbac7c comms: disable synapse password auth with MAS 2026-01-13 21:02:19 -03:00
20f99580ca comms: fix synapse runtime config injection 2026-01-13 20:59:35 -03:00
45f3315f10 comms: restore MAS and OIDC secrets in synapse 2026-01-13 20:55:36 -03:00
e154f47620 comms: fix signing key job permissions 2026-01-13 20:49:11 -03:00
f5f4649614 comms: add debug logging for signing key job 2026-01-13 20:47:54 -03:00
3554c01c1c comms: retry synapse signing key job 2026-01-13 20:45:14 -03:00