infrastructure/.sops.yaml
root dc15bb8a68 Add OPA/Conftest policies and SOPS config
Policies:
- deny_dangerous: block deletion/replace of stateful resources
- security: enforce firewall and SSH key auth on VMs
- cost_control: limit VM cores (16) and RAM (32GB)
- require_tags: warn on missing environment/managed_by tags

SOPS: age public key configured for secrets encryption.
2026-02-09 06:36:39 +01:00

6 lines
227 B
YAML

creation_rules:
- path_regex: \.secrets\.yaml$
age: age1yttnttdpafzn73mf3g8fw4x04444gymwsfrfm99fv9qkcxqzqs7sld8hln
- path_regex: secrets/.*\.yaml$
age: age1yttnttdpafzn73mf3g8fw4x04444gymwsfrfm99fv9qkcxqzqs7sld8hln