diff --git a/.github/scripts/.bash_history b/.github/scripts/.bash_history index 9b4383608..3fadf8fec 100644 --- a/.github/scripts/.bash_history +++ b/.github/scripts/.bash_history @@ -347,7 +347,7 @@ rm -rf jdk-18_linux-x64_bin.deb git rebase -i main git rebase -i master git stash -export tempPassword="1f94QXGi8zGUNiT91bconrnPLl44bCY59Y8itGyN6Yg=" +export tempPassword="dWTZkr5BPvnJYw+8sXtwQX8bCVTtsCrAL//mgrzeYTY=" mvn run tempPassword k6 npx k6 diff --git a/k8s-vault-minkube-start.sh b/k8s-vault-minkube-start.sh index 666a6f615..11786f932 100755 --- a/k8s-vault-minkube-start.sh +++ b/k8s-vault-minkube-start.sh @@ -81,6 +81,9 @@ kubectl exec vault-0 -n vault -- vault secrets enable -path=secret kv-v2 echo "Putting a secret in" kubectl exec vault-0 -n vault -- vault kv put secret/secret-challenge vaultpassword.password="$(openssl rand -base64 16)" +echo "Putting a challenge key in" +kubectl exec vault-0 -n vault -- vault kv put secret/injected vaultinjected.value="$(openssl rand -base64 16)" + echo "Putting a subkey issue in" kubectl exec vault-0 -n vault -- vault kv put secret/wrongsecret aaaauser."$(openssl rand -base64 8)"="$(openssl rand -base64 16)" @@ -115,6 +118,9 @@ path "secret/data/wrongsecret" { path "secret/data/application" { capabilities = ["read"] } +path "secret/data/injected" { + capabilities = ["read"] +} EOF' kubectl exec vault-0 -n vault -- /bin/sh -c 'vault policy write standard_sre - <