127 Commits

Author SHA1 Message Date
jenkins
9965b34534 feat(hermes): take the Anthropic credential from Vault
The Claude subscription OAuth token was created as a manual kubectl Secret in
the interest of demo time, with migration to Vault agreed as follow-up. The
value now lives at kv/atlas/hermes/agent-tokens and is injected as a file.

The hermes role gains that path and binds the hermes-triage service account
the deployment actually runs as; it previously bound only hermes-vault. The
init container prefers the Vault file and falls back to the Secret, so this
can be rolled back by removing the annotations alone, and the Secret should be
deleted once Vault has been serving it for a while.

Vault was reachable all along without the operator credential: Ariadne already
holds a vault-admin Kubernetes auth role, which is how the value was written.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-06 12:14:52 -03:00
jenkins
5f4bdc6e7e ai(hermes): add isolated user chat instance 2026-08-02 02:31:01 -03:00
jenkins
a666c6c0ad Preserve Cassandra legacy BYOK during cutover 2026-07-25 08:17:53 -03:00
jenkins
b5dd4f5058 feat(cassandra): add parallel migration infrastructure 2026-07-25 00:20:01 -03:00
jenkins
c1bcea55d2 Deploy Cassandra 0.7.65 generator worker 2026-07-24 02:04:03 -03:00
jenkins
880736b4ff agent: replace OpenClaw with Hermes 2026-07-21 21:02:44 -03:00
jenkins
af1868b06b vault: upgrade to 1.21.4 2026-07-18 14:04:08 -03:00
jenkins
13b5a98685 vault: upgrade to 1.20.4 2026-07-18 13:58:22 -03:00
jenkins
29e6ee6775 vault: upgrade to 1.19.5 2026-07-18 13:51:27 -03:00
jenkins
b33d990c22 vault: upgrade to 1.18.5 2026-07-18 13:43:18 -03:00
jenkins
662629c6f9 vault: allow admin raft snapshots 2026-07-18 13:40:04 -03:00
jenkins
ff7c42bab5 vault: discourage public indexing 2026-07-18 11:38:42 -03:00
jenkins
86895a59d5 vault: tighten public response headers 2026-07-18 11:34:54 -03:00
jenkins
69d48c7441 vault: allow ui mount detail checks 2026-07-18 08:21:25 -03:00
jenkins
0544a3b542 vault: keep ui api available 2026-07-18 08:19:50 -03:00
jenkins
77455e6dd8 vault: harden public ingress 2026-07-18 03:34:17 -03:00
jenkins
4c37dc1a47 Deploy Veles 0.4.1 runtime support 2026-06-27 19:07:16 -03:00
jenkins
74ab9bc78b gitea: wire Veles OIDC login 2026-06-20 14:08:18 -03:00
jenkins
1d20fb35d2 veles: stage atlas infrastructure 2026-06-09 00:46:46 -03:00
jenkins
5bec30bd30 game-stream: deploy Wolf foundation 2026-05-21 02:07:17 -03:00
jenkins
712b97f64b agent(openclaw): expose oauth protected UI 2026-05-20 17:22:12 -03:00
jenkins
5b9ba5b514 vault: use http health probes 2026-05-19 17:25:56 -03:00
jenkins
a194b4c9c6 recovery(post-outage): restore jellyfin and maintenance sync 2026-05-05 06:31:09 -03:00
jenkins
1917ec3e1d recovery(metis): use atlas kv node secrets 2026-04-24 17:29:58 -03:00
jenkins
5b150958a4 recovery(metis): seed per-node vault password slots 2026-04-24 17:24:37 -03:00
7b2cea7637 ci(jenkins): inject sonarqube token from vault 2026-04-21 19:43:08 -03:00
2540250ff3 vault(auth): allow maintenance soteria oidc secret path 2026-04-12 17:23:41 -03:00
deb52c424b maintenance/vault: move Metis runtime secrets to Vault 2026-04-05 11:31:05 -03:00
0828f0cf9e maintenance: inject metis SSH keys directly from Vault 2026-04-05 10:31:20 -03:00
e84399d0b1 maintenance: source metis SSH keys from Vault 2026-04-05 10:25:29 -03:00
5ae6c5d4fb maintenance: remoteize metis build and flash 2026-03-31 20:42:35 -03:00
fdc80b9c0f sso: route metis through dedicated oauth2 proxy 2026-03-31 17:32:19 -03:00
00c0375790 comms: add synapse admin ensure job 2026-01-27 04:48:44 -03:00
1b6fac86fb vault: bootstrap k8s auth config with root token 2026-01-27 01:04:57 -03:00
6062e266aa vault: allow ariadne to use vault-admin role 2026-01-26 22:26:13 -03:00
daf8be2d43 vault: unsuspend k8s auth config cronjob 2026-01-22 04:47:50 -03:00
096bb329e6 jenkins: sync harbor pull secret from vault 2026-01-22 04:45:24 -03:00
ee4af80e15 jenkins: use shared harbor creds when present 2026-01-22 03:15:38 -03:00
0ab34c0af5 ariadne: split portal and ariadne db secrets 2026-01-21 03:39:17 -03:00
0680926dae vault: allow ariadne to read needed secrets 2026-01-21 03:21:01 -03:00
587a0af1d7 maintenance: wire ariadne db and dashboards 2026-01-20 23:03:39 -03:00
f8c368b21f maintenance: extend Ariadne schedules and RBAC 2026-01-20 03:01:59 -03:00
a6b317097e fix: allow maintenance vault sync role 2026-01-19 19:07:00 -03:00
f3620aa2a4 chore: centralize harbor pull credentials 2026-01-19 19:02:14 -03:00
11a06e7683 feat: add Ariadne service and glue scheduling 2026-01-19 16:58:02 -03:00
47fdd97120 vault: allow vaultwarden mailu secret 2026-01-19 02:23:16 -03:00
e4a06c4ffb portal: use mailu smtp secret 2026-01-19 00:56:07 -03:00
84710b99e8 monitoring: add glue dashboard and tag cronjobs 2026-01-18 02:50:07 -03:00
cb5d38e979 vault: allow portal to read postmark relay 2026-01-18 01:17:52 -03:00
288f58e48c vault: pin cronjobs to service IP 2026-01-17 03:17:36 -03:00