Skip to content

[codex] add keyvault slice#9

Merged
TacoRocket merged 1 commit intomainfrom
codex/next-slice-followup
Mar 31, 2026
Merged

[codex] add keyvault slice#9
TacoRocket merged 1 commit intomainfrom
codex/next-slice-followup

Conversation

@TacoRocket
Copy link
Copy Markdown
Owner

What changed

  • added a new keyvault Phase 2 slice with management-plane inventory, findings, fixtures, schema coverage, and help wiring
  • integrated the command into CLI, registry, output rendering, all-checks, and docs

Why it changed

  • the roadmap moves from Phase 1 identity work into Phase 2 secrets, config, and resource trust
  • keyvault is the first bounded Phase 2 slice and stays evidence-based without expanding into data-plane secret enumeration yet

Impact

  • AzureFox can now surface Key Vault assets with network posture, private endpoint presence, purge protection state, RBAC mode, and access policy count
  • the new secrets section now has a first implemented command for grouped execution and help discovery

Validation

  • python3 -m pytest
  • python3 -m ruff check src/azurefox tests scripts

@TacoRocket TacoRocket merged commit 5497bdd into main Mar 31, 2026
2 checks passed
@TacoRocket TacoRocket deleted the codex/next-slice-followup branch March 31, 2026 22:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant