Generate default CA via ssh/config/ca, split composite KUBECTL for role writes, read pubkey from config/ca, allow warden key_id in roles, prefer production kubeconfig. |
||
|---|---|---|
| .. | ||
| openbao-apply-initial-config.sh | ||
| openbao-apply-ssh-engine.sh | ||
| openbao-validate-emergency-drill-evidence.sh | ||
| openbao-validate-restore-evidence.sh | ||
| openbao-verify-authenticated.sh | ||
| openbao-verify-ssh-engine.sh | ||
| openbao-verify.sh | ||