Skip to content

feat: use Vault Transit as signing service#8

Merged
paullatzelsperger merged 7 commits into
mainfrom
feat/vault_as_signing_service
May 26, 2026
Merged

feat: use Vault Transit as signing service#8
paullatzelsperger merged 7 commits into
mainfrom
feat/vault_as_signing_service

Conversation

@paullatzelsperger
Copy link
Copy Markdown
Contributor

@paullatzelsperger paullatzelsperger commented May 26, 2026

This PR uses Vault's Transit engine to sign cryptographic material to prevent the private key from ever leaving the secure enclosure.

This PR also separates the app deployment into three different sub-deployments:

  • k8s/apps/edc
  • k8s/apps/cfm
  • k8s/apps/ui

this makes un-deploying and redeploying easier.

Also, this PR adds a local docker image cache for subsequent attempts.

paullatzelsperger and others added 6 commits May 22, 2026 08:05
- Add edc-vault-transit runtime dependency to identity-hub launcher
- Add do_curl helper to seed job for proper HTTP status inspection,
  distinguishing 409 (already exists) from other errors
- Add IPC_LOCK capability to vault-agent sidecar in siglet

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@paullatzelsperger paullatzelsperger marked this pull request as ready for review May 26, 2026 10:09
@paullatzelsperger paullatzelsperger merged commit b745460 into main May 26, 2026
9 checks passed
@paullatzelsperger paullatzelsperger deleted the feat/vault_as_signing_service branch May 26, 2026 10:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants