Persist Vault audit logs on the host: permissions, HUP, and 90-day rotation
Configure the audit device, container storage, and logrotate separately, then verify that new requests reach the new file after rotation.
Tag · 6 stories
Configure the audit device, container storage, and logrotate separately, then verify that new requests reach the new file after rotation.
Keep the credential in Vault, select namespaces with labels, and verify both Secret delivery and real image pulls.
I use my GitOps repository as shared working notes, so AI can understand the current setup before helping with changes, validation, and writing.
Restricting AI access to SSH, Kubernetes, and OpenTelemetry diagnostics while keeping local LLM context small.
Move the public entry point and identity checks to Cloudflare, then reach internal services through an outbound-only Tunnel.
Deleting the file is only the first step: rotate the credential, rewrite every reachable ref, verify the remote independently, and prevent the next …