readme update #584

Merged
tech merged 1 commits from cb-582 into main 2026-02-28 19:11:28 +00:00

View File

@@ -126,11 +126,11 @@ Callbacks now authenticates to Vault through a sidecar Vault Agent (AppRole), sa
Required Vault policy (minimal read-only for KV v2 mount `kv`): Required Vault policy (minimal read-only for KV v2 mount `kv`):
```hcl ```hcl
path "kv/data/callbacks/*" { path "kv/data/sendico/callbacks/*" {
capabilities = ["read"] capabilities = ["read"]
} }
path "kv/metadata/callbacks/*" { path "kv/metadata/sendico/callbacks/*" {
capabilities = ["read", "list"] capabilities = ["read", "list"]
} }
``` ```
@@ -158,5 +158,5 @@ vault kv put kv/sendico/edge/callbacks/vault \
Store webhook signing secrets (example path consumed by `secret_ref`): Store webhook signing secrets (example path consumed by `secret_ref`):
```bash ```bash
vault kv put kv/callbacks/client-a/webhook secret="super-secret" vault kv put kv/sendico/callbacks/client-a/webhook secret="super-secret"
``` ```