Loading
skills: document vault-login prereq placement for kube and TF repos
otica-migrate-kube: add kc-render-sec: vault-login step after
kc-config: gke-login — OTICA's kube.mk has no vault prereq on
kc-render-sec; secret templates call vault-kv and need auth first.
otica-migrate-tf: add tf-render: vault-login guidance and warn against
tf-init: vault-login — tf-render runs before tf-init's recipe in the
chain, so vault-login on tf-init fires after vault is already needed.
gcp-login correctly stays on tf-init (GCS backend access).
Changelog-Added: kube: kc-render-sec: vault-login wiring step
Changelog-Added: tf: tf-render: vault-login; warn against tf-init: vault-login
Co-Authored-By:
Claude Sonnet 4.6 <noreply@anthropic.com>