Backup
Run backup for Vault
The root //:vault and //:vault.* labels delegate to wrappers in
//tools/vault/cmd/workspace, using //tools/al:config. //tools/vault:vault
is the standalone CLI; the wrappers add the existing AL environment injection.
Run backup for Vault
Get a short-lived Forgejo token using OIDC
Generate a client certificate
Generate a root token for Vault
Create a harbor session using OIDC
Secret injector
Login to vault using the yubikey
Get a login ticket using OIDC
Http terraform backend backed by Vault
Unseal the vault