0700033c0a
secrets: migrate all hosts from sops to OpenBao vault
...
Replace sops-nix secrets with OpenBao vault secrets across all hosts.
Hardcode root password hash, add extractKey option to vault-secrets
module, update Terraform with secrets/policies for all hosts, and
create AppRole provisioning playbook.
Hosts migrated: ha1, monitoring01, ns1, ns2, http-proxy, nix-cache01
Wave 1 hosts (nats1, jelly01, pgdb1) get AppRole policies only.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com >
2026-02-05 18:43:09 +01:00
3219b8da4b
nix-cache01: re-add homelab label
Run nix flake check / flake-check (push) Failing after 4m15s
Periodic flake update / flake-update (push) Successful in 2m32s
2025-08-27 23:00:47 +02:00
e5d799ef68
nix-cache01: redo actions config
Run nix flake check / flake-check (push) Has been cancelled
2025-08-27 22:57:26 +02:00
2fc4623e8d
nix-cache01: make more changes to runner
Run nix flake check / flake-check (push) Failing after 23s
2025-08-27 22:47:27 +02:00
bd162f3743
nix-cache01: make some changes to runner
Run nix flake check / flake-check (push) Failing after 12s
2025-08-27 22:42:42 +02:00
b86de01de8
nix-cache01: change runner log-level to debug
Run nix flake check / flake-check (push) Has been cancelled
2025-08-27 22:29:28 +02:00
09bd63169d
nix-cache01: add podman to host
Run nix flake check / flake-check (push) Failing after 3m41s
Periodic flake update / flake-update (push) Successful in 2m0s
2025-08-21 21:36:49 +02:00
ef3d34d27f
nix-cache01: change runner labels
Run nix flake check / flake-check (push) Failing after 4m50s
2025-08-21 21:28:14 +02:00
ad3f4e8094
nix-cache01: fix actions config secret name
Run nix flake check / flake-check (push) Has been cancelled
2025-08-21 21:00:20 +02:00
fa4e47a873
nix-cache01: fix instance name in runner
Run nix flake check / flake-check (push) Has been cancelled
2025-08-21 20:59:18 +02:00
f49711b1b3
nix-cache01: fix typo in actions config
Run nix flake check / flake-check (push) Has been cancelled
2025-08-21 20:57:02 +02:00
a0e94430b4
nix-cache01: add actions runner
Run nix flake check / flake-check (push) Has been cancelled
2025-08-21 20:56:04 +02:00