Vault

Vault

The root //:vault and //:vault.* labels delegate to wrappers in //tools/vault/cmd/workspace, using //tools/al:config. //tools/vault:vault is the standalone CLI; the wrappers add the existing AL environment injection.


Backup

Run backup for Vault

Forgejo login

Get a short-lived Forgejo token using OIDC

Gen client cert

Generate a client certificate

Gen root token

Generate a root token for Vault

Harbor login

Create a harbor session using OIDC

Injector

Secret injector

Login

Login to vault using the yubikey

PVE login

Get a login ticket using OIDC

Tf backend

Http terraform backend backed by Vault

Unseal

Unseal the vault