Vault::Client wraps token-auth REST: read_dynamic, revoke_lease, renew_lease, health. Errors surface as VaultError carrying status. VaultDynamicRotator's rotation contract leans on Vault as the secret factory: - generate: read_dynamic (Vault issues new creds + lease) - apply: no-op (Vault already provisioned) - verify: lease renewal acts as liveness check - commit: revoke OLD lease (tracked in current_lease_id tag) - rollback_apply: revoke NEW lease 8 unit specs cover client method round-trips, rotator full path with old-lease revocation, verify-on-Vault-error handling, rollback, and the no-old-lease pass-through case. |
||
|---|---|---|
| .. | ||
| .github/workflows | ||
| spec | ||
| src | ||
| .editorconfig | ||
| .gitignore | ||
| LICENSE | ||
| Makefile | ||
| README.md | ||
| shard.lock | ||
| shard.yml | ||
README.md
Credential Rotation Enforcer (cre)
A Crystal-based daemon that tracks and enforces credential rotation
policies across AWS Secrets Manager, HashiCorp Vault, GitHub fine-grained
PATs, and local .env files.
Full README, asciinema demos, and walkthrough live in
learn/. This README will be expanded in Phase 16 of the build.