Fix cicd job
This commit is contained in:
parent
77d31d6144
commit
0010c610f7
@ -48,7 +48,6 @@ spec:
|
|||||||
set -e
|
set -e
|
||||||
echo "[bootstrap for scope cicd]"
|
echo "[bootstrap for scope cicd]"
|
||||||
|
|
||||||
# המתנה לזמינות Vault
|
|
||||||
i=0
|
i=0
|
||||||
until vault status >/dev/null 2>&1; do
|
until vault status >/dev/null 2>&1; do
|
||||||
i=$((i+1))
|
i=$((i+1))
|
||||||
@ -59,10 +58,8 @@ spec:
|
|||||||
sleep 2
|
sleep 2
|
||||||
done
|
done
|
||||||
|
|
||||||
# אם צריך להפעיל KV (בזהירות, רק אם לטוקן יש הרשאות):
|
|
||||||
# vault secrets enable -version=2 -path=cicd kv 2>/dev/null || true
|
# vault secrets enable -version=2 -path=cicd kv 2>/dev/null || true
|
||||||
|
|
||||||
# מדיניות קריאה בלבד ל-KV v2
|
|
||||||
cat >/tmp/policy.hcl <<'EOF'
|
cat >/tmp/policy.hcl <<'EOF'
|
||||||
path "cicd/metadata/*" { capabilities = ["list"] }
|
path "cicd/metadata/*" { capabilities = ["list"] }
|
||||||
path "cicd/data/*" { capabilities = ["read"] }
|
path "cicd/data/*" { capabilities = ["read"] }
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user