6d224861 came from a --no-checkout worktree whose empty index made the
commit drop every file except two. This restores 05b50d2b's full tree and
correctly adds stacks/stem95su/gdrive-sync.tf + the service-catalog stem95su
entry. Forward-only (parent=6d224861, no force-push); [ci skip] since the
live infra was never applied from the broken commit.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
10 lines
494 B
Bash
Executable file
10 lines
494 B
Bash
Executable file
#!/usr/bin/env bash
|
|
# Generate a short-lived kubeconfig from Vault K8s secrets engine.
|
|
# Requires: vault login -method=oidc (or VAULT_TOKEN set)
|
|
set -euo pipefail
|
|
|
|
TOKEN=$(vault write -format=json kubernetes/creds/local-admin kubernetes_namespace=default | jq -r .data.service_account_token)
|
|
kubectl config set-credentials vault-admin --token="$TOKEN"
|
|
kubectl config set-context vault --cluster=kubernetes --user=vault-admin
|
|
kubectl config use-context vault
|
|
echo "Kubeconfig set with 1h token"
|