Adds a Loki ruler group (lane=security -> #security) for the homelab vault op-log: VaultwardenTOTPFetched (every 2nd-factor fetch is visible) and VaultwardenFetchVolumeHigh (>100 fetches/10m backstop). The audit spine (Vault audit device, reads of secret/data/workstation/claude-users/*) is already captured. True CLI-bypass detection needs cross-stream correlation (follow-up). |
||
|---|---|---|
| .. | ||
| modules/monitoring | ||
| imports.tf | ||
| main.tf | ||
| secrets | ||
| terragrunt.hcl | ||