{"parentUuid":null,"isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":"You are implementing Task C4 of an implementation plan: update the existing `README.md` of the `eks-cluster-applications` Terraform module to document the new `vector_*` variables and the data-flow change introduced by Phase B/C.\n\n## Context\n\n- Working directory: `/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications`\n- Existing `README.md` is 326 lines — established structure already in place. Read it first to understand the existing organization (e.g., how it documents the `otel_collector_*`, `fluxcd_*`, `application_deployment_*`, etc. surfaces). Match that style.\n- New `vector.tf` file (created in C1) introduces 12 new variables:\n - `vector_chart_version` (required when enabled)\n - `vector_image_tag` (required when enabled)\n - `vector_datadog_site` (required when enabled)\n - `vector_datadog_api_key_vault_path` (required when enabled)\n - `vector_external_secrets_cluster_store_name` (required when enabled — name of the ClusterSecretStore created by external-secrets module)\n - `vector_enabled_cluster_types` (map; defaults: mgmt/cps/saas=true, infra/dev=false)\n - `vector_enabled` (bool, nullable; default null)\n - `vector_image` (default `registry.ic-ops.net/cache-docker-hub/timberio/vector`)\n - `vector_replicas` (number, default 3)\n - `vector_audit_drop_patterns` (list of strings, defaults to the two Immuta audit patterns)\n - `vector_email_redaction_enabled` (bool, default true)\n - `vector_email_redaction_replacement` (string, default `[REDACTED-EMAIL]`)\n - `vector_additional_config` (any, default null — escape hatch)\n- The data flow when `vector_enabled = true`:\n - `apps → otel-lb → otel-collector → vector → Datadog`\n - Vector applies VRL transforms: drops audit log lines and redacts email addresses across logs/traces/metrics.\n- When `vector_enabled = false` (or unset): `apps → otel-lb → otel-collector → Datadog` (unchanged).\n\n## Task Description\n\n### Task C4: README updates in eks-cluster-applications\n\n**Files:**\n- Modify: `terraform/iac-library/aws/compute/eks-cluster-applications/README.md`\n\n- [ ] **Step 1: Read the existing `README.md`** thoroughly. Note where other modules' variables are documented and what the section structure looks like.\n\n- [ ] **Step 2: Add a `vector_*` section** in the appropriate place — likely alongside other in-cluster components like `otel_collector_*`, `external_secrets_*`, etc. The section should:\n\n - Briefly describe what Vector does (in-cluster aggregator that receives OTLP from the otel-collector and applies VRL transforms before shipping to Datadog).\n - Note the data-flow change: when `vector_enabled = true`, the otel-collector's terminal exporter routes through Vector instead of direct-to-Datadog. The Datadog API key moves from the otel-collector's secret reference to the Vector module's ExternalSecret.\n - Tabulate the 12 new variables (or document them in the same style as the existing variables in the README — list, table, or paragraph).\n - Cross-link to `docs/superpowers/specs/2026-05-05-vector-redaction-design.md` (the design spec, located at `/Users/steve.briggs/projects/IAC/docs/superpowers/specs/2026-05-05-vector-redaction-design.md`).\n\n- [ ] **Step 3: Add a brief note** somewhere that explains how to enable Vector for a particular cluster:\n\n ```hcl\n vector_enabled = true\n vector_chart_version = \"0.36.0\"\n vector_image_tag = \"0.40.0-distroless-libc\"\n vector_datadog_site = \"datadoghq.com\"\n vector_datadog_api_key_vault_path = \"secret/data/datadog/api-key\"\n vector_external_secrets_cluster_store_name = \"vault-cluster-store\"\n ```\n\n- [ ] **Step 4: If the existing README mentions otel_collector behavior in a way that's now changed** (e.g., \"otel-collector exports directly to Datadog\"), update that text to reflect the new dual-mode behavior (direct vs. via-Vector).\n\n- [ ] **Step 5: Self-review.** Don't break existing structure or formatting; keep additions concise and aligned with the README's existing voice.\n\n## Constraints\n\n- **DO NOT run any git commands.**\n- **DO NOT** push, tag, open MRs.\n- **DO NOT** modify any other files in this task — only `README.md` in this directory.\n\n## Spec / plan references\n\n- Spec: `/Users/steve.briggs/projects/IAC/docs/superpowers/specs/2026-05-05-vector-redaction-design.md`\n- Plan: `/Users/steve.briggs/projects/IAC/docs/superpowers/plans/2026-05-05-vector-redaction-pipeline.md` Task C4\n\n## Report Format\n\n- **Status:** DONE | DONE_WITH_CONCERNS | BLOCKED | NEEDS_CONTEXT\n- Lines added (and any modified) to README\n- Variables documented (count)\n- Whether existing otel-collector copy needed updating (and how)\n- Self-review findings"},"uuid":"e9c518fe-5a2e-4aa7-98e8-a69e972d2f4a","timestamp":"2026-05-05T19:02:56.967Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"e9c518fe-5a2e-4aa7-98e8-a69e972d2f4a","isSidechain":true,"agentId":"a995d77ad5955a4da","attachment":{"type":"deferred_tools_delta","addedNames":["CronCreate","CronDelete","CronList","EnterWorktree","ExitWorktree","Monitor","NotebookEdit","PushNotification","RemoteTrigger","TaskStop","WebFetch","WebSearch","mcp__claude_ai_Adobe_for_creativity__authenticate","mcp__claude_ai_Adobe_for_creativity__complete_authentication","mcp__claude_ai_Apollo_io__authenticate","mcp__claude_ai_Apollo_io__complete_authentication","mcp__claude_ai_Asana__authenticate","mcp__claude_ai_Asana__complete_authentication","mcp__claude_ai_Atlassian__authenticate","mcp__claude_ai_Atlassian__complete_authentication","mcp__claude_ai_Context7__query-docs","mcp__claude_ai_Context7__resolve-library-id","mcp__claude_ai_Gmail__authenticate","mcp__claude_ai_Gmail__complete_authentication","mcp__claude_ai_Google_Calendar__authenticate","mcp__claude_ai_Google_Calendar__complete_authentication","mcp__claude_ai_Google_Drive__authenticate","mcp__claude_ai_Google_Drive__complete_authentication","mcp__claude_ai_Krisp__authenticate","mcp__claude_ai_Krisp__complete_authentication","mcp__claude_ai_Lucid__authenticate","mcp__claude_ai_Lucid__complete_authentication","mcp__claude_ai_Outreach__authenticate","mcp__claude_ai_Outreach__complete_authentication","mcp__claude_ai_Pocket__authenticate","mcp__claude_ai_Pocket__complete_authentication","mcp__claude_ai_Slack__authenticate","mcp__claude_ai_Slack__complete_authentication","mcp__claude_ai_Superhuman__authenticate","mcp__claude_ai_Superhuman__complete_authentication","mcp__claude_ai_Zoom_for_Claude__authenticate","mcp__claude_ai_Zoom_for_Claude__complete_authentication","mcp__obsidian__append_to_active_file","mcp__obsidian__append_to_vault_file","mcp__obsidian__create_vault_file","mcp__obsidian__delete_active_file","mcp__obsidian__delete_vault_file","mcp__obsidian__execute_template","mcp__obsidian__fetch","mcp__obsidian__get_active_file","mcp__obsidian__get_server_info","mcp__obsidian__get_vault_file","mcp__obsidian__list_vault_files","mcp__obsidian__patch_active_file","mcp__obsidian__patch_vault_file","mcp__obsidian__search_vault","mcp__obsidian__search_vault_simple","mcp__obsidian__search_vault_smart","mcp__obsidian__show_file_in_obsidian","mcp__obsidian__update_active_file"],"addedLines":["CronCreate","CronDelete","CronList","EnterWorktree","ExitWorktree","Monitor","NotebookEdit","PushNotification","RemoteTrigger","TaskStop","WebFetch","WebSearch","mcp__claude_ai_Adobe_for_creativity__authenticate","mcp__claude_ai_Adobe_for_creativity__complete_authentication","mcp__claude_ai_Apollo_io__authenticate","mcp__claude_ai_Apollo_io__complete_authentication","mcp__claude_ai_Asana__authenticate","mcp__claude_ai_Asana__complete_authentication","mcp__claude_ai_Atlassian__authenticate","mcp__claude_ai_Atlassian__complete_authentication","mcp__claude_ai_Context7__query-docs","mcp__claude_ai_Context7__resolve-library-id","mcp__claude_ai_Gmail__authenticate","mcp__claude_ai_Gmail__complete_authentication","mcp__claude_ai_Google_Calendar__authenticate","mcp__claude_ai_Google_Calendar__complete_authentication","mcp__claude_ai_Google_Drive__authenticate","mcp__claude_ai_Google_Drive__complete_authentication","mcp__claude_ai_Krisp__authenticate","mcp__claude_ai_Krisp__complete_authentication","mcp__claude_ai_Lucid__authenticate","mcp__claude_ai_Lucid__complete_authentication","mcp__claude_ai_Outreach__authenticate","mcp__claude_ai_Outreach__complete_authentication","mcp__claude_ai_Pocket__authenticate","mcp__claude_ai_Pocket__complete_authentication","mcp__claude_ai_Slack__authenticate","mcp__claude_ai_Slack__complete_authentication","mcp__claude_ai_Superhuman__authenticate","mcp__claude_ai_Superhuman__complete_authentication","mcp__claude_ai_Zoom_for_Claude__authenticate","mcp__claude_ai_Zoom_for_Claude__complete_authentication","mcp__obsidian__append_to_active_file","mcp__obsidian__append_to_vault_file","mcp__obsidian__create_vault_file","mcp__obsidian__delete_active_file","mcp__obsidian__delete_vault_file","mcp__obsidian__execute_template","mcp__obsidian__fetch","mcp__obsidian__get_active_file","mcp__obsidian__get_server_info","mcp__obsidian__get_vault_file","mcp__obsidian__list_vault_files","mcp__obsidian__patch_active_file","mcp__obsidian__patch_vault_file","mcp__obsidian__search_vault","mcp__obsidian__search_vault_simple","mcp__obsidian__search_vault_smart","mcp__obsidian__show_file_in_obsidian","mcp__obsidian__update_active_file"],"removedNames":[],"readdedNames":[]},"type":"attachment","uuid":"ad6d6500-d785-40a6-83d5-30d1fe7fd81e","timestamp":"2026-05-05T19:02:56.969Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"ad6d6500-d785-40a6-83d5-30d1fe7fd81e","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01QfH7zv4k9TLanKWzKYU2Qh","type":"message","role":"assistant","content":[{"type":"text","text":"I'll start by reading the existing README and the spec file to understand the structure and context."}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":3,"cache_creation_input_tokens":3072,"cache_read_input_tokens":7207,"cache_creation":{"ephemeral_5m_input_tokens":3072,"ephemeral_1h_input_tokens":0},"output_tokens":1,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwWoWFC8K1Ye9k7cL1P","attributionAgent":"general-purpose","type":"assistant","uuid":"5c62679c-f24b-487a-bd1f-045b7aa276a5","timestamp":"2026-05-05T19:03:04.735Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"5c62679c-f24b-487a-bd1f-045b7aa276a5","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01QfH7zv4k9TLanKWzKYU2Qh","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_0151u147fGixbwQG41NDAg1i","name":"Read","input":{"file_path":"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md"},"caller":{"type":"direct"}}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":3,"cache_creation_input_tokens":3072,"cache_read_input_tokens":7207,"cache_creation":{"ephemeral_5m_input_tokens":3072,"ephemeral_1h_input_tokens":0},"output_tokens":1,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwWoWFC8K1Ye9k7cL1P","attributionAgent":"general-purpose","type":"assistant","uuid":"a7c77a31-9371-4786-91cc-30629536787d","timestamp":"2026-05-05T19:03:05.172Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"a7c77a31-9371-4786-91cc-30629536787d","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"type":"tool_result","content":"File content (30571 tokens) exceeds maximum allowed tokens (25000). Use offset and limit parameters to read specific portions of the file, or search for specific content instead of reading the whole file.","is_error":true,"tool_use_id":"toolu_0151u147fGixbwQG41NDAg1i"}]},"uuid":"22999b57-b21a-4612-8b7a-abcc2d7bb362","timestamp":"2026-05-05T19:03:05.421Z","toolUseResult":"Error: File content (30571 tokens) exceeds maximum allowed tokens (25000). Use offset and limit parameters to read specific portions of the file, or search for specific content instead of reading the whole file.","sourceToolAssistantUUID":"a7c77a31-9371-4786-91cc-30629536787d","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"22999b57-b21a-4612-8b7a-abcc2d7bb362","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01QfH7zv4k9TLanKWzKYU2Qh","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_01U7JaimaxL4kPGhpkgrnuHa","name":"Read","input":{"file_path":"/Users/steve.briggs/projects/IAC/docs/superpowers/specs/2026-05-05-vector-redaction-design.md"},"caller":{"type":"direct"}}],"stop_reason":"tool_use","stop_sequence":null,"stop_details":null,"usage":{"input_tokens":3,"cache_creation_input_tokens":3072,"cache_read_input_tokens":7207,"output_tokens":176,"server_tool_use":{"web_search_requests":0,"web_fetch_requests":0},"service_tier":"standard","cache_creation":{"ephemeral_1h_input_tokens":0,"ephemeral_5m_input_tokens":3072},"inference_geo":"","iterations":[{"input_tokens":3,"output_tokens":176,"cache_read_input_tokens":7207,"cache_creation_input_tokens":3072,"cache_creation":{"ephemeral_5m_input_tokens":3072,"ephemeral_1h_input_tokens":0},"type":"message"}],"speed":"standard"},"diagnostics":null},"requestId":"req_011CajwWoWFC8K1Ye9k7cL1P","attributionAgent":"general-purpose","type":"assistant","uuid":"20c2e3a3-78a4-430f-b5aa-c405c5ddc424","timestamp":"2026-05-05T19:03:05.532Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"20c2e3a3-78a4-430f-b5aa-c405c5ddc424","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_01U7JaimaxL4kPGhpkgrnuHa","type":"tool_result","content":"1\t# Vector + OpenTelemetry Redaction Pipeline — Design Spec\n2\t\n3\t**Date:** 2026-05-05\n4\t**Author:** steve.briggs@immuta.com (with Claudebob)\n5\t**Status:** Draft, pending review\n6\t\n7\t---\n8\t\n9\t## 1. Overview\n10\t\n11\t### Problem\n12\t\n13\tToday the telemetry path on EKS clusters in this org is:\n14\t\n15\t```\n16\tapps → otel-lb → otel-collector → Datadog (logs, APM, metrics)\n17\t```\n18\t\n19\tSensitive-data exclusion lives in **Datadog Agent processing rules** under\n20\t`kubernetes/applications/datadog-processing-rules`. Both `prod` and `staging` ship\n21\tthe same `rules.json` containing two `exclude_at_match` entries that drop Immuta\n22\taudit log lines before they reach Datadog. `apm.json` is empty.\n23\t\n24\tThese rules are tied to the Datadog Agent's processing pipeline and only operate\n25\ton logs. They cannot redact span attributes or metric labels, and there is no\n26\tstraightforward way to add modify-style transforms (e.g., replace email\n27\taddresses with a placeholder) within that surface.\n28\t\n29\t### Goal\n30\t\n31\tInsert **Vector** as a new in-cluster aggregator between the OTel collector and\n32\tDatadog. Vector replaces today's Datadog-side exclusion rules with VRL-based\n33\tfilter and remap transforms, applied uniformly across logs, traces, and metrics.\n34\t\n35\tThe day-1 rule set replicates today's two audit exclusions and adds email\n36\tredaction across all three signals. The architecture leaves room to grow\n37\tadditional patterns (SSN, credit cards, tokens, attribute drops, service-level\n38\tallow/deny) without further structural change.\n39\t\n40\t### Non-goals (v1)\n41\t\n42\t- Replacing the OTel collector.\n43\t- Removing the Datadog Agent (it remains for host metrics / kubelet stats).\n44\t- Decommissioning `kubernetes/applications/datadog-processing-rules` (separate effort).\n45\t- Per-cluster rule overlays beyond the Terraform variable surface.\n46\t- Dynamic / runtime-loaded rules.\n47\t- mTLS between OTel and Vector.\n48\t- Vector Agent-mode / DaemonSet collection.\n49\t\n50\t---\n51\t\n52\t## 2. Architecture\n53\t\n54\t```\n55\t [ in-cluster ]\n56\t ┌──────────┐ OTLP ┌─────────┐ OTLP ┌────────────────┐ OTLP ┌──────────────────┐ Datadog\n57\t │ apps │ ─────▶ │ otel-lb │ ─────▶ │ otel-collector │ ─────▶ │ vector aggregator│ ──────▶ Datadog SaaS\n58\t └──────────┘ └─────────┘ └────────────────┘ │ - OTLP source │ (logs, APM,\n59\t │ - VRL transforms │ metrics)\n60\t │ - Datadog sinks │\n61\t └──────────────────┘\n62\t```\n63\t\n64\t**Components:**\n65\t\n66\t- **OTel collector** keeps its current shape (`otel-lb` front tier + `otel-collector` back tier). Its terminal exporter switches from `datadog` to `otlp` (gRPC), pointed at the Vector Service.\n67\t- **Vector** runs as a Deployment with N replicas (default 3, matching OTel's tier), fronted by a ClusterIP Service. Receives OTLP, applies VRL transforms, ships to Datadog via Vector's native `datadog_logs` / `datadog_traces` / `datadog_metrics` sinks.\n68\t- **Datadog API key** moves from the OTel exporter config to Vector. Sourced from Vault via the existing `external-secrets` operator.\n69\t\n70\t**Cluster scope.** Vector is enabled on the same cluster types as the OTel\n71\tcollector by default: `mgmt`, `cps`, `saas` true; `infra`, `dev` false. A single\n72\t`vector_enabled` bool variable overrides the per-cluster-type default, matching\n73\tthe established pattern in this module.\n74\t\n75\t---\n76\t\n77\t## 3. Terraform layout\n78\t\n79\tThree changes across two repos.\n80\t\n81\t### 3.1 `internal-modules/kubernetes/monitoring/otel-collector` v1.0.7 → v1.1.0\n82\t\n83\tBackwards-compatible bump. New variables:\n84\t\n85\t| Variable | Type | Default | Purpose |\n86\t|---|---|---|---|\n87\t| `downstream_endpoint` | string | `\"\"` | When non-empty, swaps terminal exporter to OTLP |\n88\t| `downstream_protocol` | string | `\"otlp/grpc\"` | Wire protocol |\n89\t\n90\tWhen `downstream_endpoint` is non-empty, the rendered helm values gain an\n91\t`exporters.otlp` block and `service.pipelines.{logs,traces,metrics}.exporters`\n92\tswap from `[datadog]` to `[otlp]`. The Datadog exporter block and its API-key\n93\tmount fall away under the same conditional. Empty preserves today's\n94\tdirect-to-Datadog behavior — clusters that don't enable Vector see no behavioral\n95\tchange.\n96\t\n97\t### 3.2 `internal-modules/kubernetes/monitoring/vector` v1.0.0 (new module)\n98\t\n99\tMirrors the shape of the `otel-collector` internal-module: same provider wiring\n100\t(`kubernetes`, `helm`), same variable patterns, same approach to image / chart /\n101\treplica overrides.\n102\t\n103\tWhat it creates:\n104\t\n105\t- `kubernetes_namespace.vector` — the `vector` namespace.\n106\t- `kubernetes_manifest` for an `ExternalSecret` pulling the Datadog API key from Vault, using the same external-secrets cluster store the rest of the platform uses. Terraform waits for the underlying Secret object before proceeding.\n107\t- `helm_release.vector` — wraps the upstream `timberio/vector` chart with values templated from the variables below. Deployment annotated with `reloader.stakater.com/auto: \"true\"` so the existing reloader operator restarts pods on Datadog-key rotation.\n108\t\n109\tModule variables (initial set):\n110\t\n111\t| Variable | Type | Default | Purpose |\n112\t|---|---|---|---|\n113\t| `chart_version` | string | required | Vector helm chart version pin |\n114\t| `image` | string | `registry.ic-ops.net/cache-docker-hub/timberio/vector` | Image source |\n115\t| `image_tag_version` | string | required | Image tag |\n116\t| `replicas` | number | `3` | HA matches OTel collector tier |\n117\t| `datadog_site` | string | required | e.g. `datadoghq.com` / `us3.datadoghq.com` |\n118\t| `datadog_api_key_vault_path` | string | required | Vault path for ExternalSecret |\n119\t| `audit_drop_patterns` | list(string) | `[\"Audit\\\\s-\\\\s.+\", \"\\\"level\\\":\\\"audit\\\"\"]` | Day-1 exclude rules |\n120\t| `email_redaction_enabled` | bool | `true` | Toggle email redaction |\n121\t| `email_redaction_replacement` | string | `\"[REDACTED-EMAIL]\"` | Replacement marker |\n122\t| `additional_config` | any | `null` | Escape-hatch — overwrites `customConfig` wholesale, mirroring `otel_collector_additional_config` semantics |\n123\t| `resources_requests` / `resources_limits` | map | see Section 6 | Resource tuning |\n124\t\n125\t### 3.3 `eks-cluster-applications` (this repo)\n126\t\n127\t**New file `vector.tf`** — pure mirror of `otel_collector.tf`'s shape:\n128\t\n129\t```hcl\n130\tlocals {\n131\t vector_enabled = (\n132\t var.vector_enabled != null\n133\t ? var.vector_enabled\n134\t : lookup(var.vector_enabled_cluster_types, local.cluster_type, true)\n135\t )\n136\t vector_endpoint = \"http://vector.vector.svc.cluster.local:4317\"\n137\t}\n138\t\n139\tmodule \"vector\" {\n140\t source = \"git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/monitoring/vector.git?ref=v1.0.0\"\n141\t count = local.vector_enabled ? 1 : 0\n142\t\n143\t providers = {\n144\t kubernetes = kubernetes.local-cluster\n145\t helm = helm.local-cluster\n146\t }\n147\t\n148\t chart_version = var.vector_chart_version\n149\t image = var.vector_image\n150\t image_tag_version = var.vector_image_tag\n151\t replicas = var.vector_replicas\n152\t datadog_site = var.vector_datadog_site\n153\t datadog_api_key_vault_path = var.vector_datadog_api_key_vault_path\n154\t audit_drop_patterns = var.vector_audit_drop_patterns\n155\t email_redaction_enabled = var.vector_email_redaction_enabled\n156\t email_redaction_replacement = var.vector_email_redaction_replacement\n157\t additional_config = var.vector_additional_config\n158\t\n159\t depends_on = [\n160\t module.cilium,\n161\t module.external_secrets,\n162\t ]\n163\t}\n164\t```\n165\t\n166\tPlus variable declarations matching the otel-collector module's style.\n167\t`vector_enabled_cluster_types` defaults match OTel: `mgmt/cps/saas = true`,\n168\t`infra/dev = false`. A `data \"external\"` validation block enforces\n169\t`vector_enabled ⇒ external_secrets_enabled` (the Vault-backed key requires it).\n170\t\n171\t**Edits to `otel_collector.tf`:**\n172\t\n173\t- Bump `?ref=v1.0.7` → `?ref=v1.1.0`.\n174\t- Pass `downstream_endpoint = local.vector_enabled ? local.vector_endpoint : \"\"`.\n175\t- Add `depends_on = [module.vector]` so Vector's Service exists before OTel reconciles. (Belt-and-suspenders — OTLP exporter retries handle the runtime race.)\n176\t\n177\t---\n178\t\n179\t## 4. Vector configuration\n180\t\n181\tVector runs in **aggregator role** (it receives OTLP from another in-cluster\n182\tservice rather than tailing files).\n183\t\n184\t### 4.1 Pipeline topology\n185\t\n186\t```\n187\t ┌─ logs ──▶ drop_audit ──▶ redact_emails_logs ──▶ datadog_logs\n188\totlp_in (4317 │\n189\tgRPC + 4318 ─┼─ traces ──────────────────▶ redact_emails_traces ──▶ datadog_traces\n190\tHTTP) │\n191\t └─ metrics ──────────────────▶ redact_emails_metrics ──▶ datadog_metrics\n192\t```\n193\t\n194\tThree pipelines, one per signal. The `drop_audit` filter runs on logs only (the\n195\tday-1 rules are message-text patterns). Email redaction runs on all three.\n196\t\n197\t### 4.2 VRL — audit-drop filter (logs only)\n198\t\n199\tVector's `filter` transform passes events for which the condition returns\n200\t`true`, so the condition is the inverse of what gets dropped:\n201\t\n202\t```toml\n203\t[transforms.drop_audit]\n204\ttype = \"filter\"\n205\tinputs = [\"otlp_in.logs\"]\n206\tcondition = '''\n207\t msg = string!(.message ?? \"\")\n208\t !match(msg, r'Audit\\s-\\s.+') && !match(msg, r'\"level\":\"audit\"')\n209\t'''\n210\t```\n211\t\n212\t`audit_drop_patterns` is templated into the helm values from the Terraform\n213\tvariable. The default ships the two patterns from\n214\t`datadog-processing-rules/{prod,staging}/rules.json`.\n215\t\n216\t### 4.3 VRL — email-redact transform (all three signals)\n217\t\n218\tPer-signal `remap` transforms apply the same shared pattern. Log shape (the\n219\tsimple case):\n220\t\n221\t```toml\n222\t[transforms.redact_emails_logs]\n223\ttype = \"remap\"\n224\tinputs = [\"drop_audit\"]\n225\tsource = '''\n226\t email_re = r'[\\w._%+\\-]+@[\\w.-]+\\.[A-Za-z]{2,}'\n227\t\n228\t if exists(.message) {\n229\t .message = replace(string!(.message), email_re, \"[REDACTED-EMAIL]\")\n230\t }\n231\t\n232\t # walk top-level attributes for string values containing emails\n233\t if is_object(.attributes) {\n234\t .attributes = map_values(object!(.attributes)) -> |v| {\n235\t if is_string(v) { replace(v, email_re, \"[REDACTED-EMAIL]\") } else { v }\n236\t }\n237\t }\n238\t'''\n239\t```\n240\t\n241\tTrace and metric variants apply the same `map_values` walk over `attributes`\n242\tand `resource.attributes`, plus span-event attributes for traces. The email\n243\tregex and the replacement string are both templated from Terraform variables.\n244\t\n245\t**Limitation called out:** if an email is buried inside a stringified JSON\n246\tattribute value (e.g. `http.request.body` holding raw JSON text), the regex\n247\tcatches it because it operates on string content. If it's deeply nested in a\n248\tstructured object map, only values reachable by `map_values` are scanned. v1\n249\tdoes **not** recurse into nested object trees — kept simple to avoid runaway\n250\ttransform CPU on payload-heavy spans. Recursion can be added when justified.\n251\t\n252\t### 4.4 Helm values surface\n253\t\n254\tThe internal-module renders to the upstream `timberio/vector` chart:\n255\t\n256\t```yaml\n257\trole: Aggregator\n258\treplicas: {{ .Values.replicas }} # 3 by default\n259\t\n260\tcustomConfig:\n261\t data_dir: /vector-data-dir\n262\t api: { enabled: true, address: 127.0.0.1:8686 }\n263\t sources:\n264\t otlp_in:\n265\t type: opentelemetry\n266\t grpc: { address: 0.0.0.0:4317 }\n267\t http: { address: 0.0.0.0:4318 }\n268\t transforms:\n269\t drop_audit: { ... } # see 4.2\n270\t redact_emails_logs: { ... }\n271\t redact_emails_traces: { ... }\n272\t redact_emails_metrics: { ... }\n273\t sinks:\n274\t datadog_logs:\n275\t type: datadog_logs\n276\t inputs: [redact_emails_logs]\n277\t default_api_key: \"${DATADOG_API_KEY}\"\n278\t site: {{ .Values.datadogSite }}\n279\t datadog_traces: { type: datadog_traces, inputs: [redact_emails_traces], default_api_key: \"${DATADOG_API_KEY}\", site: ... }\n280\t datadog_metrics: { type: datadog_metrics, inputs: [redact_emails_metrics], default_api_key: \"${DATADOG_API_KEY}\", site: ... }\n281\t\n282\tservice:\n283\t enabled: true\n284\t type: ClusterIP\n285\t ports:\n286\t - { name: otlp-grpc, port: 4317, protocol: TCP }\n287\t - { name: otlp-http, port: 4318, protocol: TCP }\n288\t\n289\tenv:\n290\t - name: DATADOG_API_KEY\n291\t valueFrom:\n292\t secretKeyRef:\n293\t name: vector-datadog\n294\t key: api_key\n295\t\n296\tpodAnnotations:\n297\t reloader.stakater.com/auto: \"true\"\n298\t\n299\tresources:\n300\t requests: { cpu: 200m, memory: 256Mi }\n301\t limits: { cpu: 2, memory: 1Gi }\n302\t```\n303\t\n304\t`additional_config` (escape-hatch variable) when set overwrites `customConfig`\n305\twholesale, matching `otel_collector_additional_config` semantics.\n306\t\n307\t---\n308\t\n309\t## 5. OTel collector exporter swap\n310\t\n311\t### 5.1 Helm values diff\n312\t\n313\t**Before (`v1.0.7`, today):**\n314\t\n315\t```yaml\n316\texporters:\n317\t datadog:\n318\t api:\n319\t key: ${DATADOG_API_KEY}\n320\t site: datadoghq.com\n321\tservice:\n322\t pipelines:\n323\t logs: { receivers: [otlp], processors: [...], exporters: [datadog] }\n324\t traces: { receivers: [otlp], processors: [...], exporters: [datadog] }\n325\t metrics: { receivers: [otlp], processors: [...], exporters: [datadog] }\n326\t```\n327\t\n328\t**After (`v1.1.0` when `downstream_endpoint != \"\"`):**\n329\t\n330\t```yaml\n331\texporters:\n332\t otlp:\n333\t endpoint: http://vector.vector.svc.cluster.local:4317\n334\t tls:\n335\t insecure: true # in-cluster only; Cilium handles transit\n336\t sending_queue:\n337\t enabled: true\n338\t queue_size: 5000\n339\t retry_on_failure:\n340\t enabled: true\n341\t initial_interval: 5s\n342\t max_interval: 30s\n343\t max_elapsed_time: 300s\n344\tservice:\n345\t pipelines:\n346\t logs: { receivers: [otlp], processors: [...], exporters: [otlp] }\n347\t traces: { receivers: [otlp], processors: [...], exporters: [otlp] }\n348\t metrics: { receivers: [otlp], processors: [...], exporters: [otlp] }\n349\t```\n350\t\n351\tThe `exporters.datadog` block disappears. Pipeline `processors` lists are\n352\tuntouched — anything OTel does today (batching, `k8sattributes`, tail-sampling)\n353\tstays put.\n354\t\n355\t### 5.2 Datadog API key ownership\n356\t\n357\t- **Before:** OTel collector pods consume the Datadog API key (mount mechanism per the OTel internal-module's existing pattern).\n358\t- **After:** Vector module owns the secret. Its ExternalSecret creates `vector-datadog` in the `vector` namespace; Vector pods consume it via `env.DATADOG_API_KEY`. The OTel module's secret mount falls away under the same `downstream_endpoint != \"\"` conditional that gates the exporter swap.\n359\t- **Sequencing:** `module.otel_collector` has `depends_on = [module.vector]`. Single `terraform apply` brings up Vector first, then re-renders OTel.\n360\t\n361\t### 5.3 Failure-mode behavior\n362\t\n363\tIf Vector is down or unhealthy:\n364\t\n365\t- OTel's `sending_queue` buffers up to `queue_size: 5000` batches in-memory per pipeline.\n366\t- `retry_on_failure` retries with exponential backoff up to 5 minutes total.\n367\t- Past that, OTel drops batches and increments `otelcol_exporter_send_failed_*`.\n368\t- **No persistent queue in v1.** A Vector outage longer than ~5 minutes loses the buffer tail. Mitigation: Vector replica HA (3 replicas, PDB minAvailable 2). `file_storage` extension is a future hardening item.\n369\t\n370\t### 5.4 TLS posture\n371\t\n372\tOTLP between OTel and Vector runs as plain gRPC, both endpoints in-cluster.\n373\tCilium provides transport encryption. App-layer mTLS is a future hardening\n374\titem.\n375\t\n376\t### 5.5 Rollout shape (single cluster)\n377\t\n378\tSingle `terraform apply`:\n379\t\n380\t1. `module.vector` provisions — namespace, ExternalSecret, helm release reconcile to ready.\n381\t2. Same apply re-renders OTel collector helm release with `v1.1.0` and `downstream_endpoint` set — OTel pods rolling-restart with new exporter config.\n382\t3. Vector now receives all traffic; Datadog continues to receive (via Vector's sinks).\n383\t\n384\t**Rollback:** set `vector_enabled = false`. The `local.vector_endpoint` ternary\n385\tin `otel_collector.tf` falls back to `\"\"`; OTel re-renders with the original\n386\t`datadog` exporter, OTel pods rolling-restart back to direct-to-Datadog. Vector\n387\tmodule destroys cleanly. The Datadog API key path on the OTel side must remain\n388\tavailable across the rollback — this is a pre-condition; the OTel-side secret\n389\treference is not deleted in the same release that introduces Vector.\n390\t\n391\t---\n392\t\n393\t## 6. Operational concerns\n394\t\n395\t### 6.1 HA topology\n396\t\n397\t- **Replicas:** 3 default (`vector_replicas`).\n398\t- **PodDisruptionBudget:** `minAvailable: 2`.\n399\t- **Topology spread:** `topologySpreadConstraints` on `topology.kubernetes.io/zone`, `maxSkew: 1`. Module gives operators a passthrough variable to override on small clusters where AZ spread is impossible.\n400\t- **Anti-affinity:** preferred (not required) on `kubernetes.io/hostname`.\n401\t\n402\t### 6.2 Vector's own telemetry\n403\t\n404\tVector emits Prometheus-format internal metrics on `:8686/metrics`. If a\n405\tPrometheus operator (kube-prometheus-stack CRDs) is present in the cluster, the\n406\tmodule ships a `ServiceMonitor` for scraping. Otherwise, the metrics are\n407\tconsumable via the Datadog Agent's OpenMetrics check or the OTel collector\n408\titself (annotation-based scraping). The shipping mechanism is a v1\n409\timplementation question — see §8.3. Key metrics:\n410\t\n411\t| Metric | What it tells you |\n412\t|---|---|\n413\t| `vector_component_received_events_total` | Inbound rate per source/transform/sink |\n414\t| `vector_component_sent_events_total` | Outbound rate at each Datadog sink |\n415\t| `vector_component_errors_total` | Failed sends per sink |\n416\t| `vector_component_discarded_events_total` | Events dropped by `drop_audit` |\n417\t| `vector_buffer_events` | In-memory queue depth toward each Datadog sink |\n418\t| `vector_utilization` | Per-component utilization, 0–1 |\n419\t\n420\tVector's own logs go to stdout and are captured by the existing OTel pipeline.\n421\tA Vector outage means we cannot see Vector's logs through Vector. First-line\n422\tdebug: `kubectl logs -n vector`.\n423\t\n424\t### 6.3 Alerting (sketch — actual monitor wiring out of scope)\n425\t\n426\t| Condition | Severity | Why |\n427\t|---|---|---|\n428\t| `vector_component_errors_total{sink=~\"datadog_.*\"}` rate > 0 for 5m | warn | Datadog sink failing |\n429\t| `vector_buffer_events / vector_buffer_max_events > 0.8` for 5m | warn | Outbound queue filling |\n430\t| `vector_buffer_events / vector_buffer_max_events > 0.95` for 2m | page | About to drop |\n431\t| Vector ready replicas < 2 for 5m | page | Below PDB floor |\n432\t| `otelcol_exporter_send_failed_*{exporter=\"otlp\"}` rate > 0 for 5m | warn | OTel→Vector path broken |\n433\t\n434\tDatadog monitor wiring lives in this org's Datadog-as-Code surface, not the\n435\tTerraform module. **Required follow-up before declaring v1 production-ready.**\n436\t\n437\t### 6.4 Sizing & resource defaults\n438\t\n439\t```yaml\n440\tresources:\n441\t requests: { cpu: 200m, memory: 256Mi }\n442\t limits: { cpu: 2, memory: 1Gi }\n443\t```\n444\t\n445\tConservative starting points. Vector CPU usage scales with VRL transform\n446\tcomplexity (regex on every event isn't free). Real sizing comes from\n447\tobserved metrics after a soak in `mgmt`/`cps` before rolling to `saas`.\n448\t\n449\t### 6.5 Vault / ExternalSecret dependency chain\n450\t\n451\t```\n452\tVault ──▶ external-secrets operator ──▶ ExternalSecret (vector ns)\n453\t │\n454\t ▼\n455\t Secret: vector-datadog\n456\t │\n457\t ▼\n458\t Vector pods (env DATADOG_API_KEY)\n459\t```\n460\t\n461\tThe Vector module uses `kubernetes_manifest.wait` on the ExternalSecret's\n462\tmaterialized Secret to block the helm release until secret hydration completes.\n463\tWithout that wait, the helm release races ahead and Vector pods CrashLoop on\n464\tstartup. Reconcile order within the module:\n465\t\n466\t1. Namespace\n467\t2. ExternalSecret (and wait until the underlying Secret resource is observed)\n468\t3. Helm release for Vector\n469\t\n470\t### 6.6 Datadog API key rotation\n471\t\n472\tRotate the secret in Vault. ExternalSecret refreshes the in-cluster Secret. The\n473\texisting **`reloader` operator** picks up the change and restarts Vector pods —\n474\tthe Vector Deployment is annotated with `reloader.stakater.com/auto: \"true\"`.\n475\tNo manual intervention required.\n476\t\n477\t### 6.7 Bootstrap-order edge case (first-time cluster provisioning)\n478\t\n479\tA net-new cluster runs `terraform apply` once for layer-3\n480\t(`eks-cluster-applications`). Within that apply:\n481\t\n482\t1. `external_secrets` reconciles first (existing dependency).\n483\t2. `vector` reconciles next (new — `depends_on = [module.cilium, module.external_secrets]`).\n484\t3. `otel_collector` reconciles last (`depends_on = [module.vector]`).\n485\t\n486\tThere is never an OTel collector running with `downstream_endpoint` set before\n487\tVector is ready to receive.\n488\t\n489\t### 6.8 Data-loss budget for v1\n490\t\n491\t| Scenario | Loss |\n492\t|---|---|\n493\t| Vector single-pod restart | None — other replicas serve via Service load-balancing |\n494\t| Vector full-outage < 5 min | None — OTel `sending_queue` + `retry_on_failure` covers |\n495\t| Vector full-outage > 5 min | Tail of OTel queue dropped; Datadog gap proportional to outage minus 5 min |\n496\t| OTel collector full-outage | Same shape as today — apps' OTLP exporters retry/buffer per their config |\n497\t| Datadog API key rotation | None — reloader-driven pod restart |\n498\t\n499\t---\n500\t\n501\t## 7. Testing & verification plan\n502\t\n503\t### 7.1 Pre-deploy (local / CI)\n504\t\n505\t1. **Terraform plan** in a sandbox state to confirm module shape, count toggles cleanly.\n506\t2. **Helm template render** of both modules, diff against current rendered manifests in CI.\n507\t3. **`vector validate`** on the rendered config — catches VRL syntax errors. CI step in the new `internal-modules/kubernetes/monitoring/vector` repo.\n508\t4. **VRL unit tests** via `vector vrl --input ... --program ...`:\n509\t - Audit-drop: `{\"message\":\"Audit - login by user\"}` → filtered. `{\"message\":\"INFO request handled\"}` → passed.\n510\t - Email redact: `{\"message\":\"contact alice@example.com\"}` → `.message == \"contact [REDACTED-EMAIL]\"`.\n511\t - Edge: dotted addresses, plus-tag, email inside JSON-stringified attribute. Test corpus committed alongside the module.\n512\t\n513\t### 7.2 Integration (sandbox EKS cluster)\n514\t\n515\tUse a `dev`-type cluster with `vector_enabled = true` explicit override.\n516\t\n517\t1. **Smoke:** apply, confirm Vector pods Ready, OTel rolled with new `otlp` exporter, no `otelcol_exporter_send_failed`.\n518\t2. **Audit-drop:** emit log with body `Audit - test-event-`. Search Datadog for the UUID. **Pass = no result.** Repeat for `\"level\":\"audit\"`.\n519\t3. **Email-redact (logs):** emit log `Reach me at e2e-@example.com`. **Pass = log appears, body contains `[REDACTED-EMAIL]`, original local-part not present.**\n520\t4. **Email-redact (traces):** emit trace with span attribute `user.email = e2e-@example.com`. **Pass = attribute is `[REDACTED-EMAIL]` in Datadog APM.**\n521\t5. **Negative test:** emit logs containing email-shaped strings inside code blocks. Confirm regex matches and redacts. Documented as known limitation, not a failure.\n522\t\n523\t### 7.3 Failure-mode tests (sandbox)\n524\t\n525\t1. **Vector pod restart:** `kubectl delete pod -n vector -l app=vector`. Brief dip, no Datadog gap > 1m.\n526\t2. **Vector full-stop ≤ 1m:** scale to zero, wait, scale back. Queue grows then drains; no permanent drop.\n527\t3. **Vector full-stop > 5m:** expect Datadog gap of (outage − 5m). Confirms documented data-loss budget.\n528\t4. **Rollback drill:** `vector_enabled = false`, `terraform apply`. OTel reverts to `datadog` exporter, telemetry resumes.\n529\t5. **Key rotation:** rotate in Vault. Confirm reloader-driven pod restart, telemetry resumes.\n530\t\n531\t### 7.4 Production rollout sequence\n532\t\n533\t1. **Sandbox / `dev`-type cluster** — explicit opt-in, full integration suite.\n534\t2. **One `mgmt` cluster** — soak 3-7 days. Tune resource limits if needed.\n535\t3. **Remaining `mgmt` + all `cps` clusters** — incremental.\n536\t4. **`saas` clusters last**, region-by-region, lowest-risk regions first.\n537\t\n538\tEach promotion gate: green dashboards (no error-rate spikes, healthy queue\n539\tdepths) for 48h on the previous tier.\n540\t\n541\t### 7.5 Acceptance criteria for v1\n542\t\n543\t- All `*_enabled` clusters running Vector with no `otelcol_exporter_send_failed` over a 7-day window.\n544\t- Datadog ingestion volume post-rollout matches pre-rollout within ±5% (modulo the audit-drop and redaction reductions, expected and quantifiable).\n545\t- Sample query in Datadog (`@message:*@*.* AND -@message:\"\\[REDACTED-EMAIL\\]\"`) shows zero unredacted email addresses.\n546\t- Day-1 audit patterns produce zero hits in Datadog log search post-rollout.\n547\t- Datadog monitors from §6.3 deployed and silent for the first 7 days outside of planned rollout-induced restarts.\n548\t- Runbook entry added covering: Vector pod debug, queue-full triage, key rotation, rollback to direct-Datadog. (Runbook home TBD — placeholder.)\n549\t\n550\t---\n551\t\n552\t## 8. Out of scope, phased work, open questions\n553\t\n554\t### 8.1 Out of scope for v1 (restated for cross-reference)\n555\t\n556\t- Decommissioning `kubernetes/applications/datadog-processing-rules` — separate effort.\n557\t- Per-cluster rule overlay machinery beyond the Terraform variable surface.\n558\t- Dynamic / runtime-loaded rules.\n559\t- Persistent (`file_storage`) queue on the OTel collector.\n560\t- mTLS between OTel and Vector.\n561\t- Recursive descent in the email-redact VRL transform.\n562\t- Vector Agent-mode (DaemonSet) for node-level collection.\n563\t- Datadog monitor wiring (required follow-up, lives in Datadog-as-Code surface).\n564\t- Operations runbook (required follow-up, home TBD).\n565\t\n566\t### 8.2 Phased work — post-v1, in rough priority order\n567\t\n568\t1. **Expand redaction patterns:** SSN, credit cards, tokens, JWT, phone numbers. Each ships as opt-in `vector__redaction_enabled` flag in the module.\n569\t2. **Field/attribute name allow-deny lists.** `db.statement`, `http.request.body`, `aws.s3.key` — wholesale strip by attribute name via `vector_drop_attributes`.\n570\t3. **Service-level allow/deny.** Drop telemetry from services where redaction can't be exhaustive. `route` transform on `service.name`.\n571\t4. **Decommission `datadog-processing-rules`.** After Vector has been clean in prod for one quarter.\n572\t5. **Persistent OTel queue.** If the data-loss budget proves insufficient.\n573\t6. **Runtime-driven rule sources.** If redaction surface keeps growing such that Terraform applies become friction, move rules behind a `kubernetes` or `http` source.\n574\t\n575\t### 8.3 Open questions to resolve in implementation\n576\t\n577\t1. **Datadog site value origin.** Likely re-use whatever variable feeds the OTel module today; confirm during implementation by reading the OTel internal-module repo.\n578\t2. **Vault path for Datadog API key.** Same — find where OTel reads it today, point Vector at the same path. Likely the existing `external_secrets_*` variable cluster.\n579\t3. **OTel internal-module's existing secret-mount mechanism.** Affects how cleanly `v1.1.0` removes the mount when `downstream_endpoint` is set.\n580\t4. **`datadog_agent.tf` overlap.** Datadog Agent module remains for non-OTel reasons (host metrics, kubelet stats). Vector + OTel does not replace it; the Agent side is untouched.\n581\t5. **Vector self-metrics scrape mechanism.** Confirm whether a Prometheus operator with kube-prometheus-stack CRDs is present in the target cluster types. If yes, ship a `ServiceMonitor`. If no, fall back to Datadog Agent's OpenMetrics check (annotation-driven) or OTel-collector-side scraping. Decide before tagging v1.0.0 of the Vector module.\n582\t\n583\t---\n584\t\n585\t## Appendix A — File touch list\n586\t\n587\t| Repo | File | Action |\n588\t|---|---|---|\n589\t| `internal-modules/kubernetes/monitoring/otel-collector` | `main.tf`, `variables.tf`, helm values template | Add `downstream_endpoint`, `downstream_protocol` vars; conditionally render `exporters.otlp` block and gate Datadog secret mount. Tag `v1.1.0`. |\n590\t| `internal-modules/kubernetes/monitoring/vector` | (new repo) | New module v1.0.0. Namespace, ExternalSecret, helm release, ServiceMonitor, PDB. |\n591\t| `terraform/iac-library/aws/compute/eks-cluster-applications` | `vector.tf` | New file — locals, vars, `module \"vector\"` call, validation. |\n592\t| `terraform/iac-library/aws/compute/eks-cluster-applications` | `otel_collector.tf` | Bump module ref to v1.1.0; pass `downstream_endpoint`; add `depends_on = [module.vector]`. |\n593\t\n594\t## Appendix B — Day-1 rule equivalence\n595\t\n596\tSource rules in `kubernetes/applications/datadog-processing-rules/{prod,staging}/rules.json`:\n597\t\n598\t```json\n599\t[\n600\t { \"type\": \"exclude_at_match\", \"name\": \"exclude_immuta_audit\", \"pattern\": \"Audit\\\\s-\\\\s.+\" },\n601\t { \"type\": \"exclude_at_match\", \"name\": \"exclude_immuta_audit_2\", \"pattern\": \"\\\"level\\\":\\\"audit\\\"\" }\n602\t]\n603\t```\n604\t\n605\tBecomes (in Vector VRL):\n606\t\n607\t```vrl\n608\tcondition = !match(msg, r'Audit\\s-\\s.+') && !match(msg, r'\"level\":\"audit\"')\n609\t```\n610\t\n611\tPlus new email redaction across all signals (no equivalent in source rules):\n612\t\n613\t```vrl\n614\t.message = replace(string!(.message), r'[\\w._%+\\-]+@[\\w.-]+\\.[A-Za-z]{2,}', \"[REDACTED-EMAIL]\")\n615\t```\n616\t"}]},"uuid":"d45a77bc-7b3f-43a0-bc5a-34778e933986","timestamp":"2026-05-05T19:03:06.163Z","sourceToolAssistantUUID":"20c2e3a3-78a4-430f-b5aa-c405c5ddc424","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"d45a77bc-7b3f-43a0-bc5a-34778e933986","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01Hbxc8qW5DLdQMcbpddeoDJ","type":"message","role":"assistant","content":[{"type":"text","text":"Now let me read the README in sections since it's large:"}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":11761,"cache_read_input_tokens":10279,"cache_creation":{"ephemeral_5m_input_tokens":11761,"ephemeral_1h_input_tokens":0},"output_tokens":1,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":{"cache_miss_reason":{"type":"unavailable"}}},"requestId":"req_011CajwXUdiJnxHUJQix1a4D","attributionAgent":"general-purpose","type":"assistant","uuid":"b4bcf861-d3dc-4ff6-95e3-cb7ce8fa553f","timestamp":"2026-05-05T19:03:08.293Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"b4bcf861-d3dc-4ff6-95e3-cb7ce8fa553f","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01Hbxc8qW5DLdQMcbpddeoDJ","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_01SAjQR8ERNW5g1xZpDvPz3E","name":"Read","input":{"file_path":"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md","limit":100,"offset":0},"caller":{"type":"direct"}}],"stop_reason":"tool_use","stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":11761,"cache_read_input_tokens":10279,"output_tokens":133,"server_tool_use":{"web_search_requests":0,"web_fetch_requests":0},"service_tier":"standard","cache_creation":{"ephemeral_1h_input_tokens":0,"ephemeral_5m_input_tokens":11761},"inference_geo":"","iterations":[{"input_tokens":1,"output_tokens":133,"cache_read_input_tokens":10279,"cache_creation_input_tokens":11761,"cache_creation":{"ephemeral_5m_input_tokens":11761,"ephemeral_1h_input_tokens":0},"type":"message"}],"speed":"standard"},"diagnostics":{"cache_miss_reason":{"type":"unavailable"}}},"requestId":"req_011CajwXUdiJnxHUJQix1a4D","attributionAgent":"general-purpose","type":"assistant","uuid":"48ef2c6e-3144-4927-be85-bd65dc47d37f","timestamp":"2026-05-05T19:03:09.192Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"48ef2c6e-3144-4927-be85-bd65dc47d37f","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_01SAjQR8ERNW5g1xZpDvPz3E","type":"tool_result","content":"0\t## Requirements\n1\t\n2\t| Name | Version |\n3\t|------|---------|\n4\t| [terraform](#requirement\\_terraform) | >= 1.9.0 |\n5\t| [aws](#requirement\\_aws) | ~> 6.0 |\n6\t\n7\t## Providers\n8\t\n9\t| Name | Version |\n10\t|------|---------|\n11\t| [aws](#provider\\_aws) | ~> 6.0 |\n12\t| [aws.super\\_certificate\\_zone](#provider\\_aws.super\\_certificate\\_zone) | ~> 6.0 |\n13\t| [external](#provider\\_external) | n/a |\n14\t| [kubernetes.local-cluster](#provider\\_kubernetes.local-cluster) | n/a |\n15\t| [random](#provider\\_random) | n/a |\n16\t| [vault](#provider\\_vault) | n/a |\n17\t\n18\t## Modules\n19\t\n20\t| Name | Source | Version |\n21\t|------|--------|---------|\n22\t| [addon-netpol](#module\\_addon-netpol) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/security/network-policy.git | v1.1.0 |\n23\t| [application\\_deployment](#module\\_application\\_deployment) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/compute/application-deployment.git | v2.1.0 |\n24\t| [argocd](#module\\_argocd) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/compute/argocd.git | v1.4.1 |\n25\t| [aws\\_load\\_balancer\\_controller](#module\\_aws\\_load\\_balancer\\_controller) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/networking/aws-load-balancer-controller.git | v1.0.1 |\n26\t| [aws\\_load\\_balancer\\_controller\\_sa](#module\\_aws\\_load\\_balancer\\_controller\\_sa) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/aws/security/kubernetes-iam-serviceaccount.git | v7.0.0 |\n27\t| [cert\\_manager](#module\\_cert\\_manager) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/security/cert-manager.git | v1.4.0 |\n28\t| [cert\\_manager\\_sa](#module\\_cert\\_manager\\_sa) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/aws/security/kubernetes-iam-serviceaccount.git | v7.0.0 |\n29\t| [cert\\_manager\\_super\\_account](#module\\_cert\\_manager\\_super\\_account) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/aws/security/cross-account-iam-role.git | v3.0.0 |\n30\t| [cilium](#module\\_cilium) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/networking/cilium.git | v5.3.0 |\n31\t| [cluster\\_autoscaler](#module\\_cluster\\_autoscaler) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/compute/cluster-autoscaler.git | v3.0.0 |\n32\t| [cluster\\_autoscaler\\_sa](#module\\_cluster\\_autoscaler\\_sa) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/aws/security/kubernetes-iam-serviceaccount.git | v7.0.0 |\n33\t| [cluster\\_issuers](#module\\_cluster\\_issuers) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/security/cluster-issuers.git | v4.0.0 |\n34\t| [cnpg\\_operator\\_deployment](#module\\_cnpg\\_operator\\_deployment) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/compute/cnpg-operator.git | v1.0.1 |\n35\t| [coredns](#module\\_coredns) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/networking/coredns.git | v1.2.2 |\n36\t| [datadog\\_agent](#module\\_datadog\\_agent) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/monitoring/datadog-agent | v1.1.0 |\n37\t| [ebs\\_csi\\_sa](#module\\_ebs\\_csi\\_sa) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/aws/security/kubernetes-iam-serviceaccount.git | v7.0.0 |\n38\t| [external\\_dns\\_private](#module\\_external\\_dns\\_private) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/networking/external-dns.git | v1.3.2 |\n39\t| [external\\_dns\\_private\\_sa](#module\\_external\\_dns\\_private\\_sa) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/aws/security/kubernetes-iam-serviceaccount.git | v7.0.0 |\n40\t| [external\\_dns\\_public](#module\\_external\\_dns\\_public) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/networking/external-dns.git | v1.3.2 |\n41\t| [external\\_dns\\_public\\_sa](#module\\_external\\_dns\\_public\\_sa) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/aws/security/kubernetes-iam-serviceaccount.git | v7.0.0 |\n42\t| [external\\_networking](#module\\_external\\_networking) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/networking/external-networking.git | v5.1.0 |\n43\t| [external\\_secrets](#module\\_external\\_secrets) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/security/external-secrets.git | v1.2.0 |\n44\t| [fluxcd](#module\\_fluxcd) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/compute/fluxcd.git | v1.2.0 |\n45\t| [ingress\\_controller\\_private](#module\\_ingress\\_controller\\_private) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/networking/ingress-controller.git | v1.5.0 |\n46\t| [ingress\\_controller\\_public](#module\\_ingress\\_controller\\_public) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/networking/ingress-controller.git | v1.5.0 |\n47\t| [kyverno](#module\\_kyverno) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/security/kyverno.git | v3.0.0 |\n48\t| [metrics\\_server](#module\\_metrics\\_server) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/monitoring/metrics-server.git | v1.2.0 |\n49\t| [otel\\_collector](#module\\_otel\\_collector) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/monitoring/otel-collector.git | v1.0.7 |\n50\t| [reloader](#module\\_reloader) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/compute/reloader.git | v1.0.1 |\n51\t| [s3\\_csi\\_driver](#module\\_s3\\_csi\\_driver) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/storage/s3-csi-driver.git | v1.1.1 |\n52\t| [s3\\_csi\\_driver\\_sa](#module\\_s3\\_csi\\_driver\\_sa) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/aws/security/kubernetes-iam-serviceaccount.git | v7.0.0 |\n53\t| [sysdig\\_agent](#module\\_sysdig\\_agent) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/security/sysdig-agent.git | v4.0.0 |\n54\t| [teleport](#module\\_teleport) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/security/teleport-agent.git | v3.0.0 |\n55\t| [teleport\\_agent\\_sa](#module\\_teleport\\_agent\\_sa) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/aws/security/kubernetes-iam-serviceaccount.git | v7.0.0 |\n56\t| [vault\\_sidecar\\_injector](#module\\_vault\\_sidecar\\_injector) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/security/vault-sidecar-injector.git | v4.1.0 |\n57\t\n58\t## Resources\n59\t\n60\t| Name | Type |\n61\t|------|------|\n62\t| [aws_eks_addon.aws_ebs_csi_driver](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/eks_addon) | resource |\n63\t| [aws_eks_addon.kube_proxy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/eks_addon) | resource |\n64\t| [aws_iam_role_policy_attachment.ebs_csi_policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role_policy_attachment) | resource |\n65\t| [aws_vpc_security_group_ingress_rule.cluster_mesh_cidrs](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/vpc_security_group_ingress_rule) | resource |\n66\t| [kubernetes_namespace.sysdig_agent](https://registry.terraform.io/providers/hashicorp/kubernetes/latest/docs/resources/namespace) | resource |\n67\t| [kubernetes_namespace.teleport_agent_namespace](https://registry.terraform.io/providers/hashicorp/kubernetes/latest/docs/resources/namespace) | resource |\n68\t| [kubernetes_secret.sysdig_secret](https://registry.terraform.io/providers/hashicorp/kubernetes/latest/docs/resources/secret) | resource |\n69\t| [random_bytes.maglev](https://registry.terraform.io/providers/hashicorp/random/latest/docs/resources/bytes) | resource |\n70\t| [aws_caller_identity.current](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/caller_identity) | data source |\n71\t| [aws_eks_cluster.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/eks_cluster) | data source |\n72\t| [aws_eks_cluster_auth.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/eks_cluster_auth) | data source |\n73\t| [aws_iam_session_context.current](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/iam_session_context) | data source |\n74\t| [aws_route53_zone.external_dns_private](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/route53_zone) | data source |\n75\t| [aws_route53_zone.external_dns_public](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/route53_zone) | data source |\n76\t| [aws_route53_zone.instances](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/route53_zone) | data source |\n77\t| [aws_route53_zone.super](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/route53_zone) | data source |\n78\t| [external_external.application_deployment_validate](https://registry.terraform.io/providers/hashicorp/external/latest/docs/data-sources/external) | data source |\n79\t| [vault_kv_secret_v2.sysdig_agent](https://registry.terraform.io/providers/hashicorp/vault/latest/docs/data-sources/kv_secret_v2) | data source |\n80\t\n81\t## Inputs\n82\t\n83\t| Name | Description | Type | Default | Required |\n84\t|------|-------------|------|---------|:--------:|\n85\t| [account\\_name](#input\\_account\\_name) | Account name where the cluster is | `string` | n/a | yes |\n86\t| [application\\_deployment\\_branch](#input\\_application\\_deployment\\_branch) | branch on application-deployment repo to reference | `string` | `\"master\"` | no |\n87\t| [application\\_deployment\\_enabled](#input\\_application\\_deployment\\_enabled) | Override for explicitly enabling or disabling application-deployment | `bool` | `null` | no |\n88\t| [application\\_deployment\\_enabled\\_cluster\\_types](#input\\_application\\_deployment\\_enabled\\_cluster\\_types) | Types of clusters that application-deployment should be enabled on by default | `map(bool)` |
{
\"cps\": true,
\"dev\": true,
\"infra\": true,
\"mgmt\": true,
\"saas\": true
}
| no |\n89\t| [application\\_deployment\\_github\\_repo\\_url](#input\\_application\\_deployment\\_github\\_repo\\_url) | Repo URL for application-deployment in GitHub | `string` | `\"\"` | no |\n90\t| [application\\_deployment\\_prune](#input\\_application\\_deployment\\_prune) | Determines if resources removed from the application-deployment Git Repo will also be deleted by flux | `bool` | `true` | no |\n91\t| [application\\_deployment\\_refresh\\_interval](#input\\_application\\_deployment\\_refresh\\_interval) | Golang timestring for how often the target branch should be synced | `string` | `\"1m0s\"` | no |\n92\t| [application\\_deployment\\_repo\\_url](#input\\_application\\_deployment\\_repo\\_url) | Repo URL for application-deployment | `string` | `\"\"` | no |\n93\t| [argocd\\_aws\\_iam\\_role\\_arn](#input\\_argocd\\_aws\\_iam\\_role\\_arn) | Role arn that argocd should use | `string` | `\"\"` | no |\n94\t| [argocd\\_enabled](#input\\_argocd\\_enabled) | Override for explicitly enabling or disabling argocd | `bool` | `null` | no |\n95\t| [argocd\\_enabled\\_cluster\\_types](#input\\_argocd\\_enabled\\_cluster\\_types) | Types of clusters the argocd helm chart should be installed on by default | `map(string)` |
{
\"cps\": false,
\"dev\": false,
\"infra\": false,
\"mgmt\": true,
\"saas\": false
}
| no |\n96\t| [argocd\\_env\\_arch](#input\\_argocd\\_env\\_arch) | The value for the ARCH environment variable in the install-customtools init container. | `string` | `\"\"` | no |\n97\t| [argocd\\_env\\_helm\\_secrets\\_version](#input\\_argocd\\_env\\_helm\\_secrets\\_version) | The value for the HELM\\_SECRETS\\_VERSION environment variable in the install-customtools init container. | `string` | `\"\"` | no |\n98\t| [argocd\\_env\\_kubectl\\_version](#input\\_argocd\\_env\\_kubectl\\_version) | The value for the KUBECTL\\_VERSION environment variable in the install-customtools init container. | `string` | `\"\"` | no |\n99\t| [argocd\\_env\\_sops\\_version](#input\\_argocd\\_env\\_sops\\_version) | The value for the SOPS\\_VERSION environment variable in the install-customtools init container. | `string` | `\"\"` | no |"}]},"uuid":"7d6094df-f90a-452a-a4a5-5631d90f81d6","timestamp":"2026-05-05T19:03:09.483Z","sourceToolAssistantUUID":"48ef2c6e-3144-4927-be85-bd65dc47d37f","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"7d6094df-f90a-452a-a4a5-5631d90f81d6","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_016XzY6GJYLoTbaDUcb7aBPW","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_01JQapDvTbZbijBBDB36JCJA","name":"Read","input":{"file_path":"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md","limit":100,"offset":100},"caller":{"type":"direct"}}],"stop_reason":"tool_use","stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":5096,"cache_read_input_tokens":22040,"output_tokens":119,"server_tool_use":{"web_search_requests":0,"web_fetch_requests":0},"service_tier":"standard","cache_creation":{"ephemeral_1h_input_tokens":0,"ephemeral_5m_input_tokens":5096},"inference_geo":"","iterations":[{"input_tokens":1,"output_tokens":119,"cache_read_input_tokens":22040,"cache_creation_input_tokens":5096,"cache_creation":{"ephemeral_5m_input_tokens":5096,"ephemeral_1h_input_tokens":0},"type":"message"}],"speed":"standard"},"diagnostics":null},"requestId":"req_011CajwXirEdRwvhVMxreZUi","attributionAgent":"general-purpose","type":"assistant","uuid":"5496851d-e572-401f-b230-aafa21b20726","timestamp":"2026-05-05T19:03:14.012Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"5496851d-e572-401f-b230-aafa21b20726","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_01JQapDvTbZbijBBDB36JCJA","type":"tool_result","content":"100\t| [argocd\\_env\\_sops\\_version](#input\\_argocd\\_env\\_sops\\_version) | The value for the SOPS\\_VERSION environment variable in the install-customtools init container. | `string` | `\"\"` | no |\n101\t| [argocd\\_env\\_vals\\_version](#input\\_argocd\\_env\\_vals\\_version) | The value for the VALS\\_VERSION environment variable in the install-customtools init container. | `string` | `\"\"` | no |\n102\t| [argocd\\_env\\_version](#input\\_argocd\\_env\\_version) | The value for the VERSION environment variable in the install-customtools init container. | `string` | `\"\"` | no |\n103\t| [argocd\\_hostname](#input\\_argocd\\_hostname) | FQDN for ArgoCD | `string` | `\"\"` | no |\n104\t| [argocd\\_image\\_tag](#input\\_argocd\\_image\\_tag) | ArgoCD application version | `string` | `\"\"` | no |\n105\t| [argocd\\_rbac\\_policy](#input\\_argocd\\_rbac\\_policy) | ArgoCD RBAC policy in CSV format. Create a csv file and use the file() function to provide the input. | `string` | `\"\"` | no |\n106\t| [argocd\\_repo](#input\\_argocd\\_repo) | Application Deployment Repo name | `string` | `\"application-deployment\"` | no |\n107\t| [argocd\\_version](#input\\_argocd\\_version) | ArgoCD Helm Chart version | `string` | `\"\"` | no |\n108\t| [aws\\_load\\_balancer\\_controller\\_enabled](#input\\_aws\\_load\\_balancer\\_controller\\_enabled) | Override for explicitly enabling or disabling the aws load balancer | `bool` | `null` | no |\n109\t| [aws\\_load\\_balancer\\_controller\\_version](#input\\_aws\\_load\\_balancer\\_controller\\_version) | Version of aws-load-balancer-controller helm chart | `string` | `\"\"` | no |\n110\t| [aws\\_load\\_balancer\\_enabled\\_cluster\\_types](#input\\_aws\\_load\\_balancer\\_enabled\\_cluster\\_types) | Types of clusters the aws load balancer should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": false,
\"infra\": false,
\"mgmt\": true,
\"saas\": true
}
| no |\n111\t| [cert\\_manager\\_enabled](#input\\_cert\\_manager\\_enabled) | Override for explicitly enabling or disabling cert-manager | `bool` | `null` | no |\n112\t| [cert\\_manager\\_enabled\\_cluster\\_types](#input\\_cert\\_manager\\_enabled\\_cluster\\_types) | Types of clusters that cert-manager should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": true,
\"infra\": true,
\"mgmt\": true,
\"saas\": true
}
| no |\n113\t| [cert\\_manager\\_version](#input\\_cert\\_manager\\_version) | Version of cert-manager helm chart | `string` | `\"\"` | no |\n114\t| [cilium\\_audit\\_mode](#input\\_cilium\\_audit\\_mode) | Enable audit mode for policy enforcement | `bool` | `false` | no |\n115\t| [cilium\\_debug\\_enabled](#input\\_cilium\\_debug\\_enabled) | Enable cilium-agent debug logs | `bool` | `false` | no |\n116\t| [cilium\\_dnsproxy\\_debug\\_enabled](#input\\_cilium\\_dnsproxy\\_debug\\_enabled) | Enable cilium-dnsproxy debug logs | `bool` | `false` | no |\n117\t| [cilium\\_dnsproxy\\_enabled](#input\\_cilium\\_dnsproxy\\_enabled) | Enable Cilium HA DNSProxy if Cilium Enteprise is also enabled | `bool` | `true` | no |\n118\t| [cilium\\_dnsproxy\\_version](#input\\_cilium\\_dnsproxy\\_version) | Version of Cilium helm chart | `string` | `\"\"` | no |\n119\t| [cilium\\_enabled](#input\\_cilium\\_enabled) | Override for explicitly enabling or disabling cilium | `bool` | `null` | no |\n120\t| [cilium\\_enabled\\_cluster\\_types](#input\\_cilium\\_enabled\\_cluster\\_types) | Types of clusters that cilium should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": true,
\"infra\": true,
\"mgmt\": true,
\"saas\": true
}
| no |\n121\t| [cilium\\_enterprise](#input\\_cilium\\_enterprise) | Should cilium be deployed as enterprise (isovalent) or open source? | `bool` | `false` | no |\n122\t| [cilium\\_lb\\_cert\\_arn](#input\\_cilium\\_lb\\_cert\\_arn) | ARN of the ACM cert that will be associated with the LoadBalancer service | `string` | `\"\"` | no |\n123\t| [cilium\\_lb\\_eip\\_ids](#input\\_cilium\\_lb\\_eip\\_ids) | CSV of Elastic IP IDs to configure on cilium LoadBalancer service | `string` | `\"\"` | no |\n124\t| [cilium\\_lb\\_subnets](#input\\_cilium\\_lb\\_subnets) | CSV of Subnet IDs to associate with the LoadBalancer service | `string` | `\"\"` | no |\n125\t| [cilium\\_max\\_ips\\_per\\_hostname](#input\\_cilium\\_max\\_ips\\_per\\_hostname) | Maximum number of IPs that can be cached for a single hostname (chart default 50) | `number` | `100` | no |\n126\t| [cilium\\_policy\\_map\\_max](#input\\_cilium\\_policy\\_map\\_max) | Maximum size of policyMap (chart default 16384) | `number` | `32768` | no |\n127\t| [cilium\\_proxy\\_idle\\_connection\\_grace\\_period](#input\\_cilium\\_proxy\\_idle\\_connection\\_grace\\_period) | Time during which idle but previously active connections with expired DNS lookups are still considered alive (chart default 0s) | `string` | `\"60s\"` | no |\n128\t| [cilium\\_registry\\_override](#input\\_cilium\\_registry\\_override) | Registry override for quay.io for cilium resources | `string` | `\"quay.io\"` | no |\n129\t| [cilium\\_version](#input\\_cilium\\_version) | Version of Cilium helm chart | `string` | `\"\"` | no |\n130\t| [cluster\\_autoscaler\\_enabled](#input\\_cluster\\_autoscaler\\_enabled) | Override for explicitly enabling or disabling the cluster autoscaler | `bool` | `null` | no |\n131\t| [cluster\\_autoscaler\\_enabled\\_cluster\\_types](#input\\_cluster\\_autoscaler\\_enabled\\_cluster\\_types) | Types of clusters the cluster autoscaler should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": true,
\"infra\": true,
\"mgmt\": true,
\"saas\": true
}
| no |\n132\t| [cluster\\_autoscaler\\_image\\_tag](#input\\_cluster\\_autoscaler\\_image\\_tag) | Tagged Image tag of the cluster autoscaler | `string` | `\"\"` | no |\n133\t| [cluster\\_autoscaler\\_version](#input\\_cluster\\_autoscaler\\_version) | Version of cluster autoscaler helm chart | `string` | `\"\"` | no |\n134\t| [cluster\\_ca](#input\\_cluster\\_ca) | Certificate Authority for the cluster | `string` | n/a | yes |\n135\t| [cluster\\_clustermesh\\_id](#input\\_cluster\\_clustermesh\\_id) | Cluster ID for clustermesh (must be set for ClusterMesh) | `number` | `0` | no |\n136\t| [cluster\\_endpoint](#input\\_cluster\\_endpoint) | Endpoint for the cluster from the EKS CLUSTER module | `string` | n/a | yes |\n137\t| [cluster\\_id](#input\\_cluster\\_id) | ID of the working cluster (should be the same as the cluster name) | `string` | n/a | yes |\n138\t| [cluster\\_issuers\\_acme\\_server](#input\\_cluster\\_issuers\\_acme\\_server) | Letsencrypt or Google server for cert generation | `string` | `\"https://acme-v02.api.letsencrypt.org/directory\"` | no |\n139\t| [cluster\\_issuers\\_vault\\_extra\\_paths](#input\\_cluster\\_issuers\\_vault\\_extra\\_paths) | List of extra Vault paths for clusterissuers | `list(string)` | `[]` | no |\n140\t| [cluster\\_issuers\\_vault\\_primary\\_path](#input\\_cluster\\_issuers\\_vault\\_primary\\_path) | Vault path for the primary cluster issuer (if using vault, otherwise can be left blank for default) | `string` | `\"\"` | no |\n141\t| [cluster\\_mesh\\_cidrs](#input\\_cluster\\_mesh\\_cidrs) | List of CIDRs to allow for incoming cluster mesh connections (should be the CIDRs of the VPCs of the clusters in the mesh) | `list(string)` | `[]` | no |\n142\t| [cluster\\_mesh\\_connections](#input\\_cluster\\_mesh\\_connections) | List of connections that ClusterMesh should connect |
list(object({
name = string
address = string
port = number
}))
| `[]` | no |\n143\t| [cluster\\_mesh\\_domain](#input\\_cluster\\_mesh\\_domain) | Domain of clustermesh if domains are not used | `string` | `\"\"` | no |\n144\t| [cluster\\_mesh\\_enable\\_kvstoremesh](#input\\_cluster\\_mesh\\_enable\\_kvstoremesh) | Enable kvstoremesh for cluster mesh | `bool` | `true` | no |\n145\t| [cluster\\_mesh\\_enabled](#input\\_cluster\\_mesh\\_enabled) | Toggle to enable Cilium Cluster Mesh TLS config | `bool` | `false` | no |\n146\t| [cluster\\_mesh\\_lb\\_annotations](#input\\_cluster\\_mesh\\_lb\\_annotations) | Annotations for the LoadBalancer service for the ClusterMesh API Server | `map(string)` | `{}` | no |\n147\t| [cluster\\_mesh\\_replicas](#input\\_cluster\\_mesh\\_replicas) | Number of replicas for ClusterMesh API Servers | `number` | `3` | no |\n148\t| [cluster\\_mesh\\_tls\\_names](#input\\_cluster\\_mesh\\_tls\\_names) | List of names to include as SANs in the certificate for the etcd server | `list(string)` | `[]` | no |\n149\t| [cluster\\_name](#input\\_cluster\\_name) | Cluster name for the EKS cluster | `string` | n/a | yes |\n150\t| [cluster\\_oidc\\_provider\\_arn](#input\\_cluster\\_oidc\\_provider\\_arn) | OIDC Provider ARN for the current working cluster | `string` | n/a | yes |\n151\t| [cluster\\_oidc\\_provider\\_issuer](#input\\_cluster\\_oidc\\_provider\\_issuer) | ODIC Provider Issuer for the current working cluster | `string` | n/a | yes |\n152\t| [cluster\\_type](#input\\_cluster\\_type) | The type of cluster, i.e. saas, mgmt, cps, will default to extracting the type from the cluster name | `string` | `\"\"` | no |\n153\t| [cluster\\_version](#input\\_cluster\\_version) | Cluster version for the EKS cluster | `string` | n/a | yes |\n154\t| [cluster\\_worker\\_sg](#input\\_cluster\\_worker\\_sg) | Security Group for worker nodes | `string` | `\"\"` | no |\n155\t| [cm\\_domains](#input\\_cm\\_domains) | List of domain names for cert-manager to manage (must be in route53) | `list(string)` | `[]` | no |\n156\t| [cm\\_super\\_domains](#input\\_cm\\_super\\_domains) | List of domain names for cert-manager to manage (must be in route53) | `list(string)` | `[]` | no |\n157\t| [cnpg\\_operator\\_enabled](#input\\_cnpg\\_operator\\_enabled) | Override for explicitly enabling or disabling the CNPG operator | `bool` | `null` | no |\n158\t| [cnpg\\_operator\\_enabled\\_cluster\\_types](#input\\_cnpg\\_operator\\_enabled\\_cluster\\_types) | Types of clusters the CNPG operator should be enabled on by default | `map(string)` |
{
\"cps\": false,
\"dev\": false,
\"infra\": false,
\"mgmt\": false,
\"saas\": true
}
| no |\n159\t| [cnpg\\_operator\\_image\\_tag](#input\\_cnpg\\_operator\\_image\\_tag) | Image tag for the CNPG operator | `string` | `\"\"` | no |\n160\t| [cnpg\\_operator\\_version](#input\\_cnpg\\_operator\\_version) | Version of the CNPG operator helm chart | `string` | `\"\"` | no |\n161\t| [coredns\\_enabled](#input\\_coredns\\_enabled) | Override for explicitly enabling or disabling CoreDNS | `bool` | `null` | no |\n162\t| [coredns\\_enabled\\_cluster\\_types](#input\\_coredns\\_enabled\\_cluster\\_types) | Types of clusters coredns should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": true,
\"infra\": true,
\"mgmt\": true,
\"saas\": true
}
| no |\n163\t| [coredns\\_image\\_tag](#input\\_coredns\\_image\\_tag) | Helm Value: Image override for coredns | `string` | `\"\"` | no |\n164\t| [coredns\\_version](#input\\_coredns\\_version) | Version of coredns helm chart | `string` | `\"\"` | no |\n165\t| [datadog\\_agent\\_enabled](#input\\_datadog\\_agent\\_enabled) | Override for explicitly enabling or disabling otel-collector | `bool` | `null` | no |\n166\t| [datadog\\_agent\\_enabled\\_cluster\\_types](#input\\_datadog\\_agent\\_enabled\\_cluster\\_types) | Types of clusters datadog\\_agent should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": false,
\"infra\": false,
\"mgmt\": true,
\"saas\": true
}
| no |\n167\t| [datadog\\_agent\\_image\\_tag](#input\\_datadog\\_agent\\_image\\_tag) | Version of otel-collector image tag | `string` | `\"\"` | no |\n168\t| [datadog\\_agent\\_version](#input\\_datadog\\_agent\\_version) | Version of otel-collector helm chart | `string` | `\"\"` | no |\n169\t| [datadog\\_create\\_namespace](#input\\_datadog\\_create\\_namespace) | n/a | `bool` | `false` | no |\n170\t| [datadog\\_enable\\_mrds\\_monitoring](#input\\_datadog\\_enable\\_mrds\\_monitoring) | Enable multitenant RDS monitoring | `bool` | `false` | no |\n171\t| [datadog\\_enable\\_now\\_obfusicator\\_options](#input\\_datadog\\_enable\\_now\\_obfusicator\\_options) | Whether to enable the NOWRDS obfuscator options in the Datadog agent configuration. | `bool` | `false` | no |\n172\t| [datadog\\_enable\\_nowrds\\_monitoring](#input\\_datadog\\_enable\\_nowrds\\_monitoring) | Enable monitoring for NOWRDS. | `bool` | `false` | no |\n173\t| [datadog\\_now\\_obfusicator\\_options](#input\\_datadog\\_now\\_obfusicator\\_options) | A map of options to configure the NOWRDS obfuscator in the Datadog agent configuration. | `map(string)` |
{
\"replace_digits\": \"true\"
}
| no |\n174\t| [datadog\\_tags](#input\\_datadog\\_tags) | Map of tags to apply to datadog metrics | `list(string)` | `[]` | no |\n175\t| [ebs\\_csi\\_addon\\_version](#input\\_ebs\\_csi\\_addon\\_version) | Version of the AWS EBS CSI driver eks addon to use | `string` | n/a | yes |\n176\t| [enable\\_kube\\_proxy\\_replacement](#input\\_enable\\_kube\\_proxy\\_replacement) | Enables deployment of the Cilium kube-proxy replacement. Kube-proxy daemonset should be deleted and nodes rolled before this is enabled. | `bool` | `true` | no |\n177\t| [env](#input\\_env) | Environment where the cluster is | `string` | n/a | yes |\n178\t| [envoy\\_debug\\_enabled](#input\\_envoy\\_debug\\_enabled) | Toggle to enable debug logs for envoy | `bool` | `false` | no |\n179\t| [envoy\\_enabled](#input\\_envoy\\_enabled) | Toggle to enable external envoy proxy daemonset | `bool` | `false` | no |\n180\t| [external\\_dns\\_enabled\\_cluster\\_types](#input\\_external\\_dns\\_enabled\\_cluster\\_types) | Types of clusters that external dns should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": true,
\"infra\": true,
\"mgmt\": true,
\"saas\": true
}
| no |\n181\t| [external\\_dns\\_private\\_domain\\_names](#input\\_external\\_dns\\_private\\_domain\\_names) | List of domains that private external-dns can manage | `list(string)` | `[]` | no |\n182\t| [external\\_dns\\_private\\_enabled](#input\\_external\\_dns\\_private\\_enabled) | Override for explicitly enabling or disabling external-dns for private zones | `bool` | `null` | no |\n183\t| [external\\_dns\\_public\\_domain\\_names](#input\\_external\\_dns\\_public\\_domain\\_names) | List of domains that public external-dns can manage | `list(string)` | `[]` | no |\n184\t| [external\\_dns\\_public\\_enabled](#input\\_external\\_dns\\_public\\_enabled) | Override for explicitly enabling or disabling external-dns for public zones | `bool` | `null` | no |\n185\t| [external\\_dns\\_version](#input\\_external\\_dns\\_version) | Version of external-dns helm chart | `string` | `\"\"` | no |\n186\t| [external\\_networking\\_api\\_listener\\_hostname](#input\\_external\\_networking\\_api\\_listener\\_hostname) | Hostname for the api.* HTTPS listener/cert (Required if external\\_networking\\_enable is true) | `string` | `\"\"` | no |\n187\t| [external\\_networking\\_app\\_listener\\_hostname](#input\\_external\\_networking\\_app\\_listener\\_hostname) | Hostname for the app.* HTTPS listener/cert (Required if external\\_networking\\_enable is true) | `string` | `\"\"` | no |\n188\t| [external\\_networking\\_enabled](#input\\_external\\_networking\\_enabled) | Override for explicitly enabling or disabling external\\_networking | `bool` | `null` | no |\n189\t| [external\\_networking\\_enabled\\_cluster\\_types](#input\\_external\\_networking\\_enabled\\_cluster\\_types) | Types of clusters external\\_networking should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": false,
\"infra\": false,
\"mgmt\": true,
\"saas\": true
}
| no |\n190\t| [external\\_networking\\_hosted\\_listener\\_hostname](#input\\_external\\_networking\\_hosted\\_listener\\_hostname) | Hostname for the hosted HTTPS listener/cert (Required if external\\_networking\\_enable is true) | `string` | `\"\"` | no |\n191\t| [external\\_networking\\_http\\_listener\\_hostname](#input\\_external\\_networking\\_http\\_listener\\_hostname) | Listener for the HTTP host | `string` | `\"*.immutacloud.com\"` | no |\n192\t| [external\\_networking\\_ibpl\\_acceptance\\_required](#input\\_external\\_networking\\_ibpl\\_acceptance\\_required) | Determine if endpoints connecting to the inbound PrivateLink service require acceptance via the console | `bool` | `true` | no |\n193\t| [external\\_networking\\_nlb\\_deletion\\_protection](#input\\_external\\_networking\\_nlb\\_deletion\\_protection) | Enable deletion protection on inbound PrivateLink NLB (only set to false if you need to destroy it!) | `bool` | `true` | no |\n194\t| [external\\_networking\\_nlb\\_enable\\_cross\\_zone\\_load\\_balancing](#input\\_external\\_networking\\_nlb\\_enable\\_cross\\_zone\\_load\\_balancing) | Enable cross-zone load balancing on inbound PrivateLink NLB | `bool` | `true` | no |\n195\t| [external\\_networking\\_privatelink\\_listener\\_hostname](#input\\_external\\_networking\\_privatelink\\_listener\\_hostname) | Hostname for the PrivateLink HTTPS listener/cert (Required if external\\_networking\\_enable is true) | `string` | `\"\"` | no |\n196\t| [external\\_networking\\_privatelink\\_regions](#input\\_external\\_networking\\_privatelink\\_regions) | List of regions to allow connections to the inbound PrivateLink service | `list(string)` | `[]` | no |\n197\t| [external\\_networking\\_wildcard\\_listener\\_hostname](#input\\_external\\_networking\\_wildcard\\_listener\\_hostname) | Hostname for the wildcard HTTPS listener/cert (Required if external\\_networking\\_enable is true) | `string` | `\"\"` | no |\n198\t| [external\\_secrets\\_cluster\\_store\\_vault\\_path](#input\\_external\\_secrets\\_cluster\\_store\\_vault\\_path) | Vault path that the External Secrets ClusterSecretStore will be configured to access | `string` | `\"secret\"` | no |\n199\t| [external\\_secrets\\_enabled](#input\\_external\\_secrets\\_enabled) | Override for explicitly enabling or disabling external-secrets | `bool` | `null` | no |"}]},"uuid":"1d76334d-6b11-4d94-a49c-0f47d3c2d136","timestamp":"2026-05-05T19:03:14.320Z","sourceToolAssistantUUID":"5496851d-e572-401f-b230-aafa21b20726","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"1d76334d-6b11-4d94-a49c-0f47d3c2d136","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01DBDqowdMma7Ya4uXsUwknA","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_018sLjMzuxm9Ew453TmuHtHr","name":"Read","input":{"file_path":"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md","limit":130,"offset":199},"caller":{"type":"direct"}}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":7357,"cache_read_input_tokens":27136,"cache_creation":{"ephemeral_5m_input_tokens":7357,"ephemeral_1h_input_tokens":0},"output_tokens":39,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwY5WwekxhkJcYHYLNF","attributionAgent":"general-purpose","type":"assistant","uuid":"90fa21af-d599-4434-850f-a233bbdad87a","timestamp":"2026-05-05T19:03:18.117Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"90fa21af-d599-4434-850f-a233bbdad87a","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_018sLjMzuxm9Ew453TmuHtHr","type":"tool_result","content":"199\t| [external\\_secrets\\_enabled](#input\\_external\\_secrets\\_enabled) | Override for explicitly enabling or disabling external-secrets | `bool` | `null` | no |\n200\t| [external\\_secrets\\_enabled\\_cluster\\_types](#input\\_external\\_secrets\\_enabled\\_cluster\\_types) | Types of clusters that external-secrets should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": true,
\"infra\": true,
\"mgmt\": true,
\"saas\": true
}
| no |\n201\t| [external\\_secrets\\_image\\_tag](#input\\_external\\_secrets\\_image\\_tag) | tag override for external-secrets images, usually tracks helm chart version | `string` | `null` | no |\n202\t| [external\\_secrets\\_log\\_level](#input\\_external\\_secrets\\_log\\_level) | Logging level for external-secrets deployments | `string` | `\"info\"` | no |\n203\t| [external\\_secrets\\_repo\\_url](#input\\_external\\_secrets\\_repo\\_url) | OCI repo URL for external-secrets images | `string` | `\"registry.ic-ops.net/cache-ghcr/external-secrets/external-secrets\"` | no |\n204\t| [external\\_secrets\\_vault\\_secret\\_name](#input\\_external\\_secrets\\_vault\\_secret\\_name) | Vault path that the approle creds are located at, minus engine mount path | `string` | `\"team/sre/infrastructure/external-secrets-approle\"` | no |\n205\t| [external\\_secrets\\_version](#input\\_external\\_secrets\\_version) | Version of the external-secrets helm chart | `string` | `\"\"` | no |\n206\t| [flow\\_export\\_allow\\_filter\\_rules](#input\\_flow\\_export\\_allow\\_filter\\_rules) | Extra set of export allow filter rules for filtering Cilium flows, separated by \\n | `string` | `\"\"` | no |\n207\t| [flow\\_export\\_deny\\_filter\\_rules](#input\\_flow\\_export\\_deny\\_filter\\_rules) | Extra set of export deny filter rules for filtering Cilium flows, separated by \\n | `string` | `\"\"` | no |\n208\t| [fluxcd\\_cli\\_repo\\_url](#input\\_fluxcd\\_cli\\_repo\\_url) | OCI repo URL for CLI images | `string` | `\"registry.ic-ops.net/cache-ghcr/fluxcd/flux-cli\"` | no |\n209\t| [fluxcd\\_enabled](#input\\_fluxcd\\_enabled) | Override for explicitly enabling or disabling fluxcd | `bool` | `null` | no |\n210\t| [fluxcd\\_enabled\\_cluster\\_types](#input\\_fluxcd\\_enabled\\_cluster\\_types) | Types of clusters that fluxcd should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": true,
\"infra\": true,
\"mgmt\": true,
\"saas\": true
}
| no |\n211\t| [fluxcd\\_helm\\_controller\\_repo\\_url](#input\\_fluxcd\\_helm\\_controller\\_repo\\_url) | OCI repo URL for helm-controller images | `string` | `\"registry.ic-ops.net/cache-ghcr/fluxcd/helm-controller\"` | no |\n212\t| [fluxcd\\_kustomize\\_controller\\_repo\\_url](#input\\_fluxcd\\_kustomize\\_controller\\_repo\\_url) | OCI repo URL for kustomize-controller images | `string` | `\"registry.ic-ops.net/cache-ghcr/fluxcd/kustomize-controller\"` | no |\n213\t| [fluxcd\\_notification\\_controller\\_repo\\_url](#input\\_fluxcd\\_notification\\_controller\\_repo\\_url) | OCI repo URL for notification-controller images | `string` | `\"registry.ic-ops.net/cache-ghcr/fluxcd/notification-controller\"` | no |\n214\t| [fluxcd\\_source\\_controller\\_repo\\_url](#input\\_fluxcd\\_source\\_controller\\_repo\\_url) | OCI repo URL for source-controller images | `string` | `\"registry.ic-ops.net/cache-ghcr/fluxcd/source-controller\"` | no |\n215\t| [fluxcd\\_version](#input\\_fluxcd\\_version) | Version of the fluxcd helm chart | `string` | `\"\"` | no |\n216\t| [gatewayapi\\_enabled](#input\\_gatewayapi\\_enabled) | Enable the Cilium GatewayAPI controller | `bool` | `false` | no |\n217\t| [gatewayapi\\_proxyprotocol](#input\\_gatewayapi\\_proxyprotocol) | Enable ProxyProtocolv2 on the GatewayAPI services | `bool` | `false` | no |\n218\t| [global\\_segment](#input\\_global\\_segment) | Global segment for the cluster, i.e. na, eu, ap | `string` | `\"\"` | no |\n219\t| [hubble\\_enterprise\\_version](#input\\_hubble\\_enterprise\\_version) | Version of the Hubble Enterprise helm chart | `string` | `\"\"` | no |\n220\t| [hubbleui\\_version](#input\\_hubbleui\\_version) | Version of Cilium helm chart | `string` | `\"\"` | no |\n221\t| [ingress\\_controller\\_cert](#input\\_ingress\\_controller\\_cert) | ARN of the ACM cert that the Ingress Controller will set in it's LBC annotations | `string` | `\"\"` | no |\n222\t| [ingress\\_controller\\_cpu\\_request](#input\\_ingress\\_controller\\_cpu\\_request) | CPU request for ingress-controller pod | `string` | `\"250m\"` | no |\n223\t| [ingress\\_controller\\_digest](#input\\_ingress\\_controller\\_digest) | Image digest of the ingress-nginx controller | `string` | `\"\"` | no |\n224\t| [ingress\\_controller\\_elb\\_ssl\\_policy](#input\\_ingress\\_controller\\_elb\\_ssl\\_policy) | The SSL policy to attach to the ELB with the ingress-controller LoadBalancer service | `string` | `\"ELBSecurityPolicy-TLS13-1-2-Res-2021-06\"` | no |\n225\t| [ingress\\_controller\\_enabled](#input\\_ingress\\_controller\\_enabled) | Toggle to enable Cilium ingress controller | `bool` | `false` | no |\n226\t| [ingress\\_controller\\_image\\_repo](#input\\_ingress\\_controller\\_image\\_repo) | Image Repo (registy/image) of the ingress-nginx controller | `string` | `\"registry.ic-ops.net/sre/ingress-nginx/controller\"` | no |\n227\t| [ingress\\_controller\\_image\\_tag](#input\\_ingress\\_controller\\_image\\_tag) | Image tag of the Ingress Controller application | `string` | `\"\"` | no |\n228\t| [ingress\\_controller\\_max\\_replicas](#input\\_ingress\\_controller\\_max\\_replicas) | Maximum number of replicas for ingress-controller HPA | `number` | `10` | no |\n229\t| [ingress\\_controller\\_memory\\_limit](#input\\_ingress\\_controller\\_memory\\_limit) | Memory limit for ingress-controller pod | `string` | `\"1Gi\"` | no |\n230\t| [ingress\\_controller\\_memory\\_request](#input\\_ingress\\_controller\\_memory\\_request) | Memory request for ingress-controller pod | `string` | `\"500Mi\"` | no |\n231\t| [ingress\\_controller\\_min\\_replicas](#input\\_ingress\\_controller\\_min\\_replicas) | Minimum number of replicas for ingress-controller HPA | `number` | `3` | no |\n232\t| [ingress\\_controller\\_private\\_enabled](#input\\_ingress\\_controller\\_private\\_enabled) | Override for explicitly enabling or disabling the installation of the private ingress controller | `bool` | `null` | no |\n233\t| [ingress\\_controller\\_public\\_enabled](#input\\_ingress\\_controller\\_public\\_enabled) | Override for explicitly enabling or disabling the installation of the public ingress controller | `bool` | `null` | no |\n234\t| [ingress\\_controller\\_version](#input\\_ingress\\_controller\\_version) | Version of the Ingress Controller helm chart | `string` | `\"\"` | no |\n235\t| [ingress\\_enabled\\_cluster\\_types](#input\\_ingress\\_enabled\\_cluster\\_types) | Types of clusters the ingress controller should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": false,
\"infra\": false,
\"mgmt\": true,
\"saas\": false
}
| no |\n236\t| [kube\\_proxy\\_addon\\_version](#input\\_kube\\_proxy\\_addon\\_version) | Version of kube-proxy eks addon to use | `string` | `\"\"` | no |\n237\t| [kube\\_proxy\\_enabled](#input\\_kube\\_proxy\\_enabled) | Override for explicitly enabling or disabling kube-proxy | `bool` | `null` | no |\n238\t| [kyverno\\_admission\\_replicas](#input\\_kyverno\\_admission\\_replicas) | Numbers of replicas to deploy for the Kyverno admission controller. | `number` | `2` | no |\n239\t| [kyverno\\_background\\_replicas](#input\\_kyverno\\_background\\_replicas) | Numbers of replicas to deploy for the Kyverno background controller. | `number` | `2` | no |\n240\t| [kyverno\\_cleanup\\_enabled](#input\\_kyverno\\_cleanup\\_enabled) | Enables Kyverno cleanup controller deployment | `bool` | `false` | no |\n241\t| [kyverno\\_cleanup\\_replicas](#input\\_kyverno\\_cleanup\\_replicas) | Numbers of replicas to deploy for the Kyverno cleanup controller. | `number` | `2` | no |\n242\t| [kyverno\\_cluster\\_role\\_rules](#input\\_kyverno\\_cluster\\_role\\_rules) | List of rule objects that specify API Groups, resources, and verbs that allows Kyverno to access CRDs for policy enforcement. |
list(object({
api_groups = list(string)
resources = list(string)
verbs = list(string)
}))
|
[
{
\"api_groups\": [
\"gateway.networking.k8s.io\"
],
\"resources\": [
\"*\"
],
\"verbs\": [
\"get\",
\"list\",
\"watch\"
]
},
{
\"api_groups\": [
\"cilium.io\"
],
\"resources\": [
\"*\"
],
\"verbs\": [
\"get\",
\"list\",
\"watch\"
]
},
{
\"api_groups\": [
\"acme.cert-manager.io\"
],
\"resources\": [
\"*\"
],
\"verbs\": [
\"get\",
\"list\",
\"watch\"
]
},
{
\"api_groups\": [
\"cert-manager.io\"
],
\"resources\": [
\"*\"
],
\"verbs\": [
\"get\",
\"list\",
\"watch\"
]
},
{
\"api_groups\": [
\"external-secrets.io\"
],
\"resources\": [
\"*\"
],
\"verbs\": [
\"get\",
\"list\",
\"watch\"
]
},
{
\"api_groups\": [
\"generators.external-secrets.io\"
],
\"resources\": [
\"*\"
],
\"verbs\": [
\"get\",
\"list\",
\"watch\"
]
},
{
\"api_groups\": [
\"source.toolkit.fluxcd.io\"
],
\"resources\": [
\"*\"
],
\"verbs\": [
\"get\",
\"list\",
\"watch\"
]
},
{
\"api_groups\": [
\"helm.toolkit.fluxcd.io\"
],
\"resources\": [
\"*\"
],
\"verbs\": [
\"get\",
\"list\",
\"watch\"
]
},
{
\"api_groups\": [
\"kustomize.toolkit.fluxcd.io\"
],
\"resources\": [
\"*\"
],
\"verbs\": [
\"get\",
\"list\",
\"watch\"
]
},
{
\"api_groups\": [
\"platform.immuta.io\"
],
\"resources\": [
\"*\"
],
\"verbs\": [
\"get\",
\"list\",
\"watch\"
]
},
{
\"api_groups\": [
\"postgresql.cnpg.io\"
],
\"resources\": [
\"*\"
],
\"verbs\": [
\"get\",
\"list\",
\"watch\"
]
}
]
| no |\n243\t| [kyverno\\_enabled](#input\\_kyverno\\_enabled) | Override for explicitly enabling or disabling the kyverno | `bool` | `null` | no |\n244\t| [kyverno\\_enabled\\_cluster\\_types](#input\\_kyverno\\_enabled\\_cluster\\_types) | Types of clusters that kyverno should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": false,
\"infra\": false,
\"mgmt\": true,
\"saas\": true
}
| no |\n245\t| [kyverno\\_install\\_crds](#input\\_kyverno\\_install\\_crds) | Enables installation of Kyverno CRDs | `bool` | `true` | no |\n246\t| [kyverno\\_log\\_format](#input\\_kyverno\\_log\\_format) | Format of outputted logs from Kyverno controllers | `string` | `\"json\"` | no |\n247\t| [kyverno\\_log\\_verbosity](#input\\_kyverno\\_log\\_verbosity) | What log level Kyverno should operate at. | `number` | `2` | no |\n248\t| [kyverno\\_reports\\_replicas](#input\\_kyverno\\_reports\\_replicas) | Numbers of replicas to deploy for the Kyverno reports controller. | `number` | `2` | no |\n249\t| [kyverno\\_version](#input\\_kyverno\\_version) | Version of the kyverno helm chart | `string` | `\"\"` | no |\n250\t| [maglev\\_config](#input\\_maglev\\_config) | Optional configuration for Maglev load balancing algorithm. |
object({
enabled = bool
table_size = number
hash_seed = string
})
|
{
\"enabled\": true,
\"hash_seed\": \"\",
\"table_size\": 16381
}
| no |\n251\t| [metrics\\_server\\_enabled](#input\\_metrics\\_server\\_enabled) | Override for explicitly enabling or disabling the metrics server | `bool` | `null` | no |\n252\t| [metrics\\_server\\_enabled\\_cluster\\_types](#input\\_metrics\\_server\\_enabled\\_cluster\\_types) | Types of clusters the metrics server should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": true,
\"infra\": true,
\"mgmt\": true,
\"saas\": true
}
| no |\n253\t| [metrics\\_server\\_image\\_tag](#input\\_metrics\\_server\\_image\\_tag) | metrics-server version tag | `string` | `\"\"` | no |\n254\t| [metrics\\_server\\_version](#input\\_metrics\\_server\\_version) | Version of metrics-server helm chart | `string` | `\"\"` | no |\n255\t| [node\\_encryption\\_enabled](#input\\_node\\_encryption\\_enabled) | Enables Node Encryption on clusters | `bool` | `true` | no |\n256\t| [otel\\_collector\\_additional\\_config](#input\\_otel\\_collector\\_additional\\_config) | Alternate helm chart config to be used (overwrites entire helm config, does not merge) | `any` | `null` | no |\n257\t| [otel\\_collector\\_enabled](#input\\_otel\\_collector\\_enabled) | Override for explicitly enabling or disabling otel-collector | `bool` | `null` | no |\n258\t| [otel\\_collector\\_enabled\\_cluster\\_types](#input\\_otel\\_collector\\_enabled\\_cluster\\_types) | Types of clusters otel\\_collector should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": false,
\"infra\": false,
\"mgmt\": true,
\"saas\": true
}
| no |\n259\t| [otel\\_collector\\_image\\_tag](#input\\_otel\\_collector\\_image\\_tag) | Version of otel-collector image tag | `string` | `\"\"` | no |\n260\t| [otel\\_collector\\_replicas](#input\\_otel\\_collector\\_replicas) | number of replicas for the otel collector/processor to have | `number` | `3` | no |\n261\t| [otel\\_collector\\_version](#input\\_otel\\_collector\\_version) | Version of otel-collector helm chart | `string` | `\"\"` | no |\n262\t| [otel\\_image](#input\\_otel\\_image) | image for the otel collector/processor | `string` | `\"registry.ic-ops.net/cache-docker-hub/otel/opentelemetry-collector-contrib\"` | no |\n263\t| [otel\\_lb\\_image](#input\\_otel\\_lb\\_image) | image for the otel collector loadbalancer | `string` | `\"registry.ic-ops.net/cache-docker-hub/otel/opentelemetry-collector-contrib\"` | no |\n264\t| [otel\\_lb\\_replicas](#input\\_otel\\_lb\\_replicas) | number of replicas for the otel loadbalancer to have | `number` | `3` | no |\n265\t| [private\\_ingress\\_proxy\\_read\\_timeout](#input\\_private\\_ingress\\_proxy\\_read\\_timeout) | Maximum time (between reads) to read proxied server response | `number` | `300` | no |\n266\t| [private\\_ingress\\_proxy\\_send\\_timeout](#input\\_private\\_ingress\\_proxy\\_send\\_timeout) | Maximum time (between writes) to send proxied server request | `number` | `300` | no |\n267\t| [private\\_ingress\\_proxy\\_stream\\_timeout](#input\\_private\\_ingress\\_proxy\\_stream\\_timeout) | Maximum time between two successive read or write operations on client or proxied server connections | `number` | `600` | no |\n268\t| [proxy\\_enable\\_transparent\\_mode](#input\\_proxy\\_enable\\_transparent\\_mode) | Toggle to enable DNS Transparency Mode (fix for ITSM-3425) | `bool` | `true` | no |\n269\t| [public\\_ingress\\_proxy\\_read\\_timeout](#input\\_public\\_ingress\\_proxy\\_read\\_timeout) | Maximum time (between reads) to read proxied server response | `number` | `300` | no |\n270\t| [public\\_ingress\\_proxy\\_send\\_timeout](#input\\_public\\_ingress\\_proxy\\_send\\_timeout) | Maximum time (between writes) to send proxied server request | `number` | `300` | no |\n271\t| [public\\_ingress\\_proxy\\_stream\\_timeout](#input\\_public\\_ingress\\_proxy\\_stream\\_timeout) | Maximum time between two successive read or write operations on client or proxied server connections | `number` | `600` | no |\n272\t| [region](#input\\_region) | Region where the cluster is | `string` | n/a | yes |\n273\t| [reloader\\_enabled](#input\\_reloader\\_enabled) | Override for explicitly enabling or disabling reloader | `bool` | `null` | no |\n274\t| [reloader\\_enabled\\_cluster\\_types](#input\\_reloader\\_enabled\\_cluster\\_types) | Types of clusters that reloader should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": true,
\"infra\": true,
\"mgmt\": true,
\"saas\": true
}
| no |\n275\t| [reloader\\_image\\_tag](#input\\_reloader\\_image\\_tag) | Image version for the reloader controller | `string` | `\"\"` | no |\n276\t| [reloader\\_repo\\_url](#input\\_reloader\\_repo\\_url) | OCI repo URL for reloader images | `string` | `\"registry.ic-ops.net/cache-ghcr/stakater/reloader\"` | no |\n277\t| [reloader\\_version](#input\\_reloader\\_version) | Version of the reloader helm chart | `string` | `\"\"` | no |\n278\t| [s3\\_csi\\_driver\\_enabled](#input\\_s3\\_csi\\_driver\\_enabled) | Override to explicitly enable or disable the s3 csi driver | `bool` | `null` | no |\n279\t| [s3\\_csi\\_driver\\_enabled\\_cluster\\_types](#input\\_s3\\_csi\\_driver\\_enabled\\_cluster\\_types) | Types of clusters the s3 csi driver should be enabled on by default | `map(string)` |
{
\"cps\": false,
\"dev\": false,
\"infra\": true,
\"mgmt\": false,
\"saas\": true
}
| no |\n280\t| [s3\\_csi\\_driver\\_image\\_tag](#input\\_s3\\_csi\\_driver\\_image\\_tag) | Image version/tag for the s3 csi driver | `string` | `\"\"` | no |\n281\t| [s3\\_csi\\_driver\\_version](#input\\_s3\\_csi\\_driver\\_version) | Helm chart version for the s3 csi driver | `string` | `\"\"` | no |\n282\t| [s3\\_csi\\_liveness\\_probe\\_repo](#input\\_s3\\_csi\\_liveness\\_probe\\_repo) | S3 CSI driver livenessProbe repo | `string` | `\"registry.ic-ops.net/cache-k8s-registry/sig-storage/livenessprobe\"` | no |\n283\t| [s3\\_csi\\_liveness\\_probe\\_tag](#input\\_s3\\_csi\\_liveness\\_probe\\_tag) | S3 CSI driver livenessProbe tag | `string` | `\"\"` | no |\n284\t| [s3\\_csi\\_node\\_driver\\_registrar\\_repo](#input\\_s3\\_csi\\_node\\_driver\\_registrar\\_repo) | S3 CSI driver nodeDriverRegistrar repo | `string` | `\"registry.ic-ops.net/cache-k8s-registry/sig-storage/csi-node-driver-registrar\"` | no |\n285\t| [s3\\_csi\\_node\\_driver\\_registrar\\_tag](#input\\_s3\\_csi\\_node\\_driver\\_registrar\\_tag) | S3 CSI driver nodeDriverRegistrar tag | `string` | `\"\"` | no |\n286\t| [subnet\\_ids](#input\\_subnet\\_ids) | List of subnets to deploy the cluster into | `list(string)` | n/a | yes |\n287\t| [sysdig\\_agent\\_enabled](#input\\_sysdig\\_agent\\_enabled) | Override for explicitly enabling or disabling the sysdig agent | `bool` | `null` | no |\n288\t| [sysdig\\_agent\\_enabled\\_cluster\\_types](#input\\_sysdig\\_agent\\_enabled\\_cluster\\_types) | Types of clusters that the sysdig agent should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": false,
\"infra\": false,
\"mgmt\": true,
\"saas\": true
}
| no |\n289\t| [sysdig\\_agent\\_version](#input\\_sysdig\\_agent\\_version) | Version of the sysdig helm chart that will be deployed | `string` | `\"\"` | no |\n290\t| [sysdig\\_cluster\\_log\\_level](#input\\_sysdig\\_cluster\\_log\\_level) | Log level for the sysdig cluster, valid values are: trace, debug, info, warn, err | `string` | `\"warn\"` | no |\n291\t| [sysdig\\_cluster\\_replica\\_count](#input\\_sysdig\\_cluster\\_replica\\_count) | Number of replicas for the sysdig cluster | `number` | `2` | no |\n292\t| [sysdig\\_host\\_log\\_level](#input\\_sysdig\\_host\\_log\\_level) | Log level for the sysdig host, valid values are: or none, debug, info, warning, error | `string` | `\"warning\"` | no |\n293\t| [sysdig\\_vault\\_mount](#input\\_sysdig\\_vault\\_mount) | mount for the sysdig vault secret | `string` | `\"secret\"` | no |\n294\t| [sysdig\\_vault\\_name](#input\\_sysdig\\_vault\\_name) | secret name | `string` | `\"team/sre/infrastructure/sysdig\"` | no |\n295\t| [tags](#input\\_tags) | Map of key-value pairs to tag created resources with. | `map(any)` | `{}` | no |\n296\t| [teleport\\_agent\\_enabled](#input\\_teleport\\_agent\\_enabled) | Override for explicitly enabling or disabling the teleport agent | `bool` | `null` | no |\n297\t| [teleport\\_agent\\_enabled\\_cluster\\_types](#input\\_teleport\\_agent\\_enabled\\_cluster\\_types) | Types of clusters that the teleport agent should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": true,
\"infra\": true,
\"mgmt\": true,
\"saas\": true
}
| no |\n298\t| [teleport\\_agent\\_proxy\\_apps](#input\\_teleport\\_agent\\_proxy\\_apps) | A map of applications for the teleport agent to proxy |
list(object({
name = string
uri = string
insecure_skip_verify = optional(bool, false)
rewrite = optional(object({
jwt_claims = optional(string)
redirect = optional(list(string), [])
headers = optional(list(string), [])
}))
labels = map(string)
}))
| `[]` | no |\n299\t| [teleport\\_agent\\_proxy\\_apps\\_resources](#input\\_teleport\\_agent\\_proxy\\_apps\\_resources) | A list of map of application resource targets that should be proxied by teleport application service |
list(object({
labels = map(string)
}))
| `[]` | no |\n300\t| [teleport\\_agent\\_version](#input\\_teleport\\_agent\\_version) | Version of Teleport Agent and helm chart | `string` | `\"\"` | no |\n301\t| [teleport\\_cluster](#input\\_teleport\\_cluster) | Teleport Cluster location | `string` | `\"transporter.ic-ops.com:443\"` | no |\n302\t| [teleport\\_os\\_databases](#input\\_teleport\\_os\\_databases) | List of OpenSearch Databases for Teleport Agent Connections |
list(object({
name = string
uri = string
protocol = optional(string, \"opensearch\")
region = string
account_id = string
labels = optional(map(string))
users = optional(list(string), [\"immuta_view\", \"immuta_admin\"])
}))
| `[]` | no |\n303\t| [teleport\\_rds\\_databases](#input\\_teleport\\_rds\\_databases) | List of RDS Databases for Teleport Agent Connections |
list(object({
name = string
uri = string
protocol = optional(string, \"postgres\")
region = string
instance_id = optional(string)
labels = optional(map(string), {})
account_id = string
resource_id = optional(string)
users = optional(list(string), [\"immuta_view\", \"immuta_admin\"])
}))
| `[]` | no |\n304\t| [teleport\\_roles](#input\\_teleport\\_roles) | List of roles, comma separated, for the teleport-agent to assume in Teleport cluster | `string` | `\"kube\"` | no |\n305\t| [trust\\_manager\\_authorized\\_secrets](#input\\_trust\\_manager\\_authorized\\_secrets) | List of secret names that trust-manager is authorize to write to | `list(string)` | `[]` | no |\n306\t| [trust\\_manager\\_authorized\\_secrets\\_all\\_enabled](#input\\_trust\\_manager\\_authorized\\_secrets\\_all\\_enabled) | Enables trust-manager to write to all secrets in the cluster | `bool` | `false` | no |\n307\t| [trust\\_manager\\_enabled](#input\\_trust\\_manager\\_enabled) | Override for explicitly enabling or disabling trust-manager | `bool` | `null` | no |\n308\t| [trust\\_manager\\_enabled\\_cluster\\_types](#input\\_trust\\_manager\\_enabled\\_cluster\\_types) | Types of clusters that trust-manager should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": false,
\"infra\": false,
\"mgmt\": true,
\"saas\": true
}
| no |\n309\t| [trust\\_manager\\_secret\\_targets\\_enabled](#input\\_trust\\_manager\\_secret\\_targets\\_enabled) | Enables trust-manager to write target secrets in bundles | `bool` | `true` | no |\n310\t| [trust\\_manager\\_version](#input\\_trust\\_manager\\_version) | Version of trust-manager helm chart | `string` | `\"\"` | no |\n311\t| [update\\_strategy\\_max\\_unavailable](#input\\_update\\_strategy\\_max\\_unavailable) | Max unavailable for the sysdig agent update strategy | `string` | `\"25%\"` | no |\n312\t| [vault\\_endpoint](#input\\_vault\\_endpoint) | Endpoint for vault, used in helm values for vault sidecar injector | `string` | `\"https://vault.infrastructure.immuta.io:8200\"` | no |\n313\t| [vault\\_sidecar\\_injector\\_enabled](#input\\_vault\\_sidecar\\_injector\\_enabled) | Override for enabling or disabling the vault sidecar injector | `bool` | `null` | no |\n314\t| [vault\\_sidecar\\_injector\\_enabled\\_cluster\\_types](#input\\_vault\\_sidecar\\_injector\\_enabled\\_cluster\\_types) | Types of clusters that vault sidecar injector should be enabled on by default | `map(string)` |
{
\"cps\": false,
\"dev\": false,
\"infra\": false,
\"mgmt\": false,
\"saas\": true
}
| no |\n315\t| [vault\\_sidecar\\_injector\\_image\\_tag](#input\\_vault\\_sidecar\\_injector\\_image\\_tag) | Image tag for the vault sidecar injector | `string` | `\"\"` | no |\n316\t| [vault\\_sidecar\\_injector\\_logformat](#input\\_vault\\_sidecar\\_injector\\_logformat) | Logging format for vault sidecar | `string` | `\"json\"` | no |\n317\t| [vault\\_sidecar\\_injector\\_loglevel](#input\\_vault\\_sidecar\\_injector\\_loglevel) | Logging level for vault sidecar | `string` | `\"warn\"` | no |\n318\t| [vault\\_sidecar\\_injector\\_version](#input\\_vault\\_sidecar\\_injector\\_version) | Version of the Vault helm chart, used to deploy the sidecar injector | `string` | `\"\"` | no |\n319\t| [vpc\\_id](#input\\_vpc\\_id) | VPC in which to deploy the cluster | `string` | n/a | yes |\n320\t| [wireguard\\_enabled](#input\\_wireguard\\_enabled) | Enables Wireguard Encryption on clusters | `bool` | `true` | no |\n321\t\n322\t## Outputs\n323\t\n324\t| Name | Description |\n325\t|------|-------------|\n326\t| [s3\\_csi\\_access\\_role\\_arn](#output\\_s3\\_csi\\_access\\_role\\_arn) | S3 CSI Driver Role Arn |\n327\t"}]},"uuid":"343bec94-c3e7-4001-b2db-58e3fc157804","timestamp":"2026-05-05T19:03:18.788Z","sourceToolAssistantUUID":"90fa21af-d599-4434-850f-a233bbdad87a","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"343bec94-c3e7-4001-b2db-58e3fc157804","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01UWZv8SBG77kXk9RTUQX3pb","type":"message","role":"assistant","content":[{"type":"text","text":"Now I have a complete picture of the README structure. It's a Terraform-docs-generated file with:\n- Requirements, Providers, Modules, Resources sections (auto-generated table format)\n- Inputs table (alphabetically sorted, all variables in one big table)\n- Outputs table\n\nThe README does NOT have hand-written narrative sections — it's purely the auto-generated terraform-docs format. The `otel_collector_*` variables are just rows in the big Inputs table, not a separate narrative section. \n\nGiven this is a terraform-docs style README, I need to add the `vector_*` variables as rows in the Inputs table (alphabetically sorted), add `module_vector` to the Modules table, and add a narrative section. Let me check if there's any custom content at the top that I might have missed by starting at line 0:"}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":10733,"cache_read_input_tokens":34493,"cache_creation":{"ephemeral_5m_input_tokens":10733,"ephemeral_1h_input_tokens":0},"output_tokens":2,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwYQhraB6CB4Z4tUAML","attributionAgent":"general-purpose","type":"assistant","uuid":"4d7155ff-b8dc-4159-ab6b-1c0d0a8bfbd4","timestamp":"2026-05-05T19:03:25.078Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"4d7155ff-b8dc-4159-ab6b-1c0d0a8bfbd4","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01UWZv8SBG77kXk9RTUQX3pb","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_016EmuNhZD16dRQnuwmm4YKT","name":"Bash","input":{"command":"wc -l \"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md\"","description":"Count lines in README"},"caller":{"type":"direct"}}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":10733,"cache_read_input_tokens":34493,"cache_creation":{"ephemeral_5m_input_tokens":10733,"ephemeral_1h_input_tokens":0},"output_tokens":2,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwYQhraB6CB4Z4tUAML","attributionAgent":"general-purpose","type":"assistant","uuid":"8ec17715-465f-4e6a-a86d-f508585cb5ca","timestamp":"2026-05-05T19:03:26.199Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"8ec17715-465f-4e6a-a86d-f508585cb5ca","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01UWZv8SBG77kXk9RTUQX3pb","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_0125G93mWAco3QpkbT7hU6XE","name":"Bash","input":{"command":"ls \"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/\"","description":"List files in directory"},"caller":{"type":"direct"}}],"stop_reason":"tool_use","stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":10733,"cache_read_input_tokens":34493,"output_tokens":386,"server_tool_use":{"web_search_requests":0,"web_fetch_requests":0},"service_tier":"standard","cache_creation":{"ephemeral_1h_input_tokens":0,"ephemeral_5m_input_tokens":10733},"inference_geo":"","iterations":[{"input_tokens":1,"output_tokens":386,"cache_read_input_tokens":34493,"cache_creation_input_tokens":10733,"cache_creation":{"ephemeral_5m_input_tokens":10733,"ephemeral_1h_input_tokens":0},"type":"message"}],"speed":"standard"},"diagnostics":null},"requestId":"req_011CajwYQhraB6CB4Z4tUAML","attributionAgent":"general-purpose","type":"assistant","uuid":"567a6803-4a2a-4332-b599-9bd07733fc43","timestamp":"2026-05-05T19:03:26.540Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"8ec17715-465f-4e6a-a86d-f508585cb5ca","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_016EmuNhZD16dRQnuwmm4YKT","type":"tool_result","content":" 326 /Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md","is_error":false}]},"uuid":"3d3db448-4a90-4eef-969a-74425999c9d3","timestamp":"2026-05-05T19:03:26.553Z","sourceToolAssistantUUID":"8ec17715-465f-4e6a-a86d-f508585cb5ca","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"567a6803-4a2a-4332-b599-9bd07733fc43","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_0125G93mWAco3QpkbT7hU6XE","type":"tool_result","content":"\u001b[38;5;6m\u001b[1md\u001b[0m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m352\u001b[39m \u001b[38;2;255;233;170mB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 12:13:52 2026\u001b[39m \u001b[38;5;6m\u001b[1m..\u001b[0m\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m3.0\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 12:13:53 2026\u001b[39m .gitignore\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m4.0\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 12:13:53 2026\u001b[39m application_deployment.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m6.1\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 12:13:53 2026\u001b[39m argocd_mgmt.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m4.0\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 12:13:53 2026\u001b[39m cluster_autoscaler.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m2.7\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 12:13:53 2026\u001b[39m cnpg_operator.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m7.1\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 12:13:53 2026\u001b[39m common.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m2.2\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 12:13:53 2026\u001b[39m coredns.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m2.3\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 12:13:53 2026\u001b[39m ebs_csi.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m3.4\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 12:13:53 2026\u001b[39m external_secrets.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m1.9\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 12:13:53 2026\u001b[39m kube_proxy.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m5.4\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 12:13:53 2026\u001b[39m kyverno.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m2.5\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 12:13:53 2026\u001b[39m metrics_server.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m2.8\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 12:13:53 2026\u001b[39m netpol.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m2.7\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 12:13:53 2026\u001b[39m reloader.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m5.2\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 12:13:53 2026\u001b[39m s3_csi.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m3.3\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 12:13:53 2026\u001b[39m vault_sidecar_injector.tf\n\u001b[38;5;6m\u001b[1md\u001b[0m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m256\u001b[39m \u001b[38;2;255;233;170mB\u001b[39m \u001b[38;2;166;179;204mFri Mar 6 16:17:40 2026\u001b[39m \u001b[38;5;6m\u001b[1m.idea\u001b[0m\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m9.1\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mWed Apr 8 11:01:45 2026\u001b[39m cert_manager.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m14\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mWed Apr 8 11:01:45 2026\u001b[39m cilium.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m6.6\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mWed Apr 8 11:01:45 2026\u001b[39m external_dns.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m6.7\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;166;179;204mWed Apr 8 11:01:45 2026\u001b[39m teleport.tf\n\u001b[38;5;6m\u001b[1md\u001b[0m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m128\u001b[39m \u001b[38;2;255;233;170mB\u001b[39m \u001b[38;2;98;209;150mTue May 5 12:28:44 2026\u001b[39m \u001b[38;5;6m\u001b[1m.claude\u001b[0m\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m66\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;98;209;150mTue May 5 12:42:37 2026\u001b[39m README.md\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m10\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;98;209;150mTue May 5 12:42:37 2026\u001b[39m aws_loadbalancer.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m4.1\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;98;209;150mTue May 5 12:42:37 2026\u001b[39m datadog_agent.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m6.7\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;98;209;150mTue May 5 12:42:37 2026\u001b[39m external_networking.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m3.6\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;98;209;150mTue May 5 12:42:37 2026\u001b[39m fluxcd.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m8.0\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;98;209;150mTue May 5 12:42:37 2026\u001b[39m ingress_controller.tf\n\u001b[38;5;6m\u001b[1md\u001b[0m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m128\u001b[39m \u001b[38;2;255;233;170mB\u001b[39m \u001b[38;2;149;255;164mTue May 5 14:52:45 2026\u001b[39m \u001b[38;5;6m\u001b[1m.terraform\u001b[0m\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m7.6\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;149;255;164mTue May 5 14:53:12 2026\u001b[39m .terraform.lock.hcl\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m4.8\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;149;255;164mTue May 5 14:54:27 2026\u001b[39m sysdig_agent.tf\n\u001b[38;5;6m\u001b[1md\u001b[0m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m512\u001b[39m \u001b[38;2;255;233;170mB\u001b[39m \u001b[38;2;149;255;164mTue May 5 14:54:27 2026\u001b[39m \u001b[38;5;6m\u001b[1m.git\u001b[0m\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m5.9\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;149;255;164mTue May 5 14:54:41 2026\u001b[39m vector.tf\n.\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m3.8\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;149;255;164mTue May 5 15:02:00 2026\u001b[39m otel_collector.tf\n\u001b[38;5;6m\u001b[1md\u001b[0m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;255;179;120mw\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;98;209;150mr\u001b[39m\u001b[38;2;166;179;204m-\u001b[39m\u001b[38;2;255;84;88mx\u001b[39m\u001b[38;2;99;242;241m\u001b[39m \u001b[38;2;255;233;170msteve.briggs\u001b[39m \u001b[38;2;255;179;120mstaff\u001b[39m \u001b[38;2;255;233;170m1.1\u001b[39m \u001b[38;2;255;233;170mKB\u001b[39m \u001b[38;2;149;255;164mTue May 5 15:02:00 2026\u001b[39m \u001b[38;5;6m\u001b[1m.\u001b[0m","is_error":false}]},"uuid":"0377abd6-4164-4943-ae6c-1e72945ef48c","timestamp":"2026-05-05T19:03:26.857Z","sourceToolAssistantUUID":"567a6803-4a2a-4332-b599-9bd07733fc43","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"0377abd6-4164-4943-ae6c-1e72945ef48c","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01PaMRsNNizM6eS6bM6uceYF","type":"message","role":"assistant","content":[{"type":"text","text":"The README is 66KB and 326 lines — it's much larger than the token limit suggested. The 326-line count matches what I read. Wait, the file shows 66KB but only 326 lines? That's because the table rows are very wide. Let me check the README more carefully — it appears terraform-docs generated, so the file starts at line 0 (which is actually `## Requirements` — there's no preamble/header block). \n\nNow let me read `vector.tf` and `otel_collector.tf` to understand what's there:"}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":9530,"cache_read_input_tokens":45226,"cache_creation":{"ephemeral_5m_input_tokens":9530,"ephemeral_1h_input_tokens":0},"output_tokens":1,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwZ19nXtU1SRzJvLrwp","attributionAgent":"general-purpose","type":"assistant","uuid":"d43ce0c4-e5b8-44bc-add0-cf246bbff911","timestamp":"2026-05-05T19:03:31.882Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"d43ce0c4-e5b8-44bc-add0-cf246bbff911","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01PaMRsNNizM6eS6bM6uceYF","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_01PjmeKijAqBj8XEJvwoDuLD","name":"Read","input":{"file_path":"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/vector.tf"},"caller":{"type":"direct"}}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":9530,"cache_read_input_tokens":45226,"cache_creation":{"ephemeral_5m_input_tokens":9530,"ephemeral_1h_input_tokens":0},"output_tokens":1,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwZ19nXtU1SRzJvLrwp","attributionAgent":"general-purpose","type":"assistant","uuid":"ee2c556e-e481-4d1a-bbd1-e50286ef7fbd","timestamp":"2026-05-05T19:03:32.671Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"ee2c556e-e481-4d1a-bbd1-e50286ef7fbd","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_01PjmeKijAqBj8XEJvwoDuLD","type":"tool_result","content":"1\t# ---------------------------------------------------------------------------------------------------------------------\n2\t# VECTOR\n3\t# ---------------------------------------------------------------------------------------------------------------------\n4\tlocals {\n5\t vector_enabled = (\n6\t var.vector_enabled != null\n7\t ? var.vector_enabled\n8\t : lookup(var.vector_enabled_cluster_types, local.cluster_type, true)\n9\t )\n10\t vector_endpoint = \"http://vector.vector.svc.cluster.local:4317\"\n11\t}\n12\t\n13\tmodule \"vector\" {\n14\t source = \"git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/monitoring/vector.git?ref=v1.0.0\"\n15\t count = local.vector_enabled ? 1 : 0\n16\t\n17\t providers = {\n18\t kubernetes = kubernetes.local-cluster\n19\t helm = helm.local-cluster\n20\t }\n21\t\n22\t chart_version = var.vector_chart_version\n23\t image = var.vector_image\n24\t image_tag_version = var.vector_image_tag\n25\t replicas = var.vector_replicas\n26\t datadog_site = var.vector_datadog_site\n27\t datadog_api_key_vault_path = var.vector_datadog_api_key_vault_path\n28\t audit_drop_patterns = var.vector_audit_drop_patterns\n29\t email_redaction_enabled = var.vector_email_redaction_enabled\n30\t email_redaction_replacement = var.vector_email_redaction_replacement\n31\t additional_config = var.vector_additional_config\n32\t\n33\t # NOTE: The external-secrets internal-module (v1.2.0) has an empty outputs.tf\n34\t # and does not expose cluster_secret_store_name. Until that output is added\n35\t # to the external-secrets module, the ClusterSecretStore name is passed\n36\t # explicitly via var.vector_external_secrets_cluster_store_name.\n37\t # TODO: replace with module.external_secrets[0].cluster_secret_store_name\n38\t # once the external-secrets internal-module exposes that output.\n39\t external_secrets_cluster_store_name = var.vector_external_secrets_cluster_store_name\n40\t\n41\t depends_on = [\n42\t module.cilium,\n43\t module.external_secrets,\n44\t ]\n45\t}\n46\t\n47\tdata \"external\" \"vector_validate\" {\n48\t count = local.vector_enabled && !local.external_secrets_enabled ? 1 : 0\n49\t\n50\t program = [\"Error: vector can only be set if external-secrets is enabled as well\"]\n51\t}\n52\t\n53\t# ---------------------------------------------------------------------------------------------------------------------\n54\t# REQUIRED PARAMETERS\n55\t# These variables must be set.\n56\t# ---------------------------------------------------------------------------------------------------------------------\n57\tvariable \"vector_chart_version\" {\n58\t description = \"Version of vector helm chart\"\n59\t type = string\n60\t default = \"\"\n61\t validation {\n62\t condition = var.vector_chart_version == \"\" && local.vector_enabled ? false : true\n63\t error_message = \"vector_chart_version must be set when vector is enabled\"\n64\t }\n65\t}\n66\t\n67\tvariable \"vector_image_tag\" {\n68\t description = \"Vector image tag\"\n69\t type = string\n70\t default = \"\"\n71\t validation {\n72\t condition = var.vector_image_tag == \"\" && local.vector_enabled ? false : true\n73\t error_message = \"vector_image_tag must be set when vector is enabled\"\n74\t }\n75\t}\n76\t\n77\tvariable \"vector_datadog_site\" {\n78\t description = \"Datadog site for vector sinks (e.g. datadoghq.com)\"\n79\t type = string\n80\t default = \"\"\n81\t validation {\n82\t condition = var.vector_datadog_site == \"\" && local.vector_enabled ? false : true\n83\t error_message = \"vector_datadog_site must be set when vector is enabled\"\n84\t }\n85\t}\n86\t\n87\tvariable \"vector_datadog_api_key_vault_path\" {\n88\t description = \"Vault path for the Datadog API key (consumed by ExternalSecret in vector ns)\"\n89\t type = string\n90\t default = \"\"\n91\t validation {\n92\t condition = var.vector_datadog_api_key_vault_path == \"\" && local.vector_enabled ? false : true\n93\t error_message = \"vector_datadog_api_key_vault_path must be set when vector is enabled\"\n94\t }\n95\t}\n96\t\n97\tvariable \"vector_external_secrets_cluster_store_name\" {\n98\t description = \"Name of the ClusterSecretStore to use for vector ExternalSecret resources. Pass the name created by the external-secrets module (typically 'vault-cluster-store'). Required when vector is enabled.\"\n99\t type = string\n100\t default = \"\"\n101\t validation {\n102\t condition = var.vector_external_secrets_cluster_store_name == \"\" && local.vector_enabled ? false : true\n103\t error_message = \"vector_external_secrets_cluster_store_name must be set when vector is enabled\"\n104\t }\n105\t}\n106\t\n107\t# ---------------------------------------------------------------------------------------------------------------------\n108\t# OPTIONAL PARAMETERS\n109\t# These variables are configurable, but have reasonable defaults set.\n110\t# ---------------------------------------------------------------------------------------------------------------------\n111\tvariable \"vector_enabled_cluster_types\" {\n112\t description = \"Types of clusters Vector should be enabled on by default\"\n113\t type = map(string)\n114\t default = {\n115\t \"mgmt\" = true\n116\t \"cps\" = true\n117\t \"saas\" = true\n118\t \"infra\" = false\n119\t \"dev\" = false\n120\t }\n121\t}\n122\t\n123\tvariable \"vector_enabled\" {\n124\t description = \"Override for explicitly enabling or disabling Vector\"\n125\t type = bool\n126\t default = null\n127\t}\n128\t\n129\tvariable \"vector_image\" {\n130\t description = \"Image for Vector\"\n131\t type = string\n132\t default = \"registry.ic-ops.net/cache-docker-hub/timberio/vector\"\n133\t}\n134\t\n135\tvariable \"vector_replicas\" {\n136\t description = \"Number of Vector aggregator replicas\"\n137\t type = number\n138\t default = 3\n139\t}\n140\t\n141\tvariable \"vector_audit_drop_patterns\" {\n142\t description = \"Regex patterns; matching log message bodies are dropped\"\n143\t type = list(string)\n144\t default = [\n145\t \"Audit\\\\s-\\\\s.+\",\n146\t \"\\\"level\\\":\\\"audit\\\"\",\n147\t ]\n148\t}\n149\t\n150\tvariable \"vector_email_redaction_enabled\" {\n151\t description = \"Toggle the email-redact VRL transform across all signals\"\n152\t type = bool\n153\t default = true\n154\t}\n155\t\n156\tvariable \"vector_email_redaction_replacement\" {\n157\t description = \"String that replaces matched email addresses\"\n158\t type = string\n159\t default = \"[REDACTED-EMAIL]\"\n160\t}\n161\t\n162\tvariable \"vector_additional_config\" {\n163\t description = \"Alternate helm chart customConfig (overwrites entire helm config)\"\n164\t type = any\n165\t default = null\n166\t}\n167\t"}]},"uuid":"af6cb525-faa6-48e7-9b14-95d8ece55aa0","timestamp":"2026-05-05T19:03:33.014Z","sourceToolAssistantUUID":"ee2c556e-e481-4d1a-bbd1-e50286ef7fbd","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"af6cb525-faa6-48e7-9b14-95d8ece55aa0","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01PaMRsNNizM6eS6bM6uceYF","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_01XLN4n7BWCXLJBdJGPq4kLi","name":"Read","input":{"file_path":"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/otel_collector.tf"},"caller":{"type":"direct"}}],"stop_reason":"tool_use","stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":9530,"cache_read_input_tokens":45226,"output_tokens":284,"server_tool_use":{"web_search_requests":0,"web_fetch_requests":0},"service_tier":"standard","cache_creation":{"ephemeral_1h_input_tokens":0,"ephemeral_5m_input_tokens":9530},"inference_geo":"","iterations":[{"input_tokens":1,"output_tokens":284,"cache_read_input_tokens":45226,"cache_creation_input_tokens":9530,"cache_creation":{"ephemeral_5m_input_tokens":9530,"ephemeral_1h_input_tokens":0},"type":"message"}],"speed":"standard"},"diagnostics":null},"requestId":"req_011CajwZ19nXtU1SRzJvLrwp","attributionAgent":"general-purpose","type":"assistant","uuid":"0e17e081-a938-4dd4-a4b3-677f867722a0","timestamp":"2026-05-05T19:03:33.036Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"0e17e081-a938-4dd4-a4b3-677f867722a0","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_01XLN4n7BWCXLJBdJGPq4kLi","type":"tool_result","content":"1\t# ---------------------------------------------------------------------------------------------------------------------\n2\t# METRICS SERVER\n3\t# ---------------------------------------------------------------------------------------------------------------------\n4\tlocals {\n5\t otel_collector_enabled = (\n6\t var.otel_collector_enabled != null\n7\t ? var.otel_collector_enabled\n8\t : lookup(var.otel_collector_enabled_cluster_types, local.cluster_type, true)\n9\t )\n10\t}\n11\t\n12\t# OTEL Collector\n13\tmodule \"otel_collector\" {\n14\t source = \"git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/monitoring/otel-collector.git?ref=v1.1.0\"\n15\t count = local.otel_collector_enabled ? 1 : 0\n16\t\n17\t providers = {\n18\t kubernetes = kubernetes.local-cluster\n19\t helm = helm.local-cluster\n20\t }\n21\t\n22\t chart_version = var.otel_collector_version\n23\t otellb_image = var.otel_lb_image\n24\t otel_image = var.otel_image\n25\t otel_lb_replicas = var.otel_lb_replicas\n26\t otel_collector_replicas = var.otel_collector_replicas\n27\t image_tag_version = var.otel_collector_image_tag\n28\t downstream_endpoint = local.vector_enabled ? local.vector_endpoint : \"\"\n29\t\n30\t depends_on = [\n31\t module.vector,\n32\t ]\n33\t}\n34\t\n35\t# ---------------------------------------------------------------------------------------------------------------------\n36\t# REQUIRED PARAMETERS\n37\t# These variables must be set.\n38\t# ---------------------------------------------------------------------------------------------------------------------\n39\tvariable \"otel_collector_version\" {\n40\t description = \"Version of otel-collector helm chart\"\n41\t type = string\n42\t default = \"\"\n43\t validation {\n44\t condition = var.otel_collector_version == \"\" && local.otel_collector_enabled ? false : true\n45\t error_message = \"otel_collector_version must be set when otel_collector is enabled\"\n46\t }\n47\t}\n48\t\n49\tvariable \"otel_collector_image_tag\" {\n50\t description = \"Version of otel-collector image tag\"\n51\t type = string\n52\t default = \"\"\n53\t validation {\n54\t condition = var.otel_collector_image_tag == \"\" && local.otel_collector_enabled ? false : true\n55\t error_message = \"otel_collector_image_tag must be set when otel_collector is enabled\"\n56\t }\n57\t}\n58\t\n59\t# ---------------------------------------------------------------------------------------------------------------------\n60\t# OPTIONAL PARAMETERS\n61\t# These variables are configurable, but have reasonable defaults set.\n62\t# ---------------------------------------------------------------------------------------------------------------------\n63\tvariable \"otel_collector_enabled_cluster_types\" {\n64\t description = \"Types of clusters otel_collector should be enabled on by default\"\n65\t type = map(string)\n66\t default = {\n67\t \"mgmt\" = true\n68\t \"cps\" = true\n69\t \"saas\" = true\n70\t \"infra\" = false\n71\t \"dev\" = false\n72\t }\n73\t}\n74\t\n75\tvariable \"otel_collector_enabled\" {\n76\t description = \"Override for explicitly enabling or disabling otel-collector\"\n77\t type = bool\n78\t default = null\n79\t}\n80\t\n81\tvariable \"otel_lb_image\" {\n82\t description = \"image for the otel collector loadbalancer\"\n83\t type = string\n84\t default = \"registry.ic-ops.net/cache-docker-hub/otel/opentelemetry-collector-contrib\"\n85\t}\n86\t\n87\tvariable \"otel_image\" {\n88\t description = \"image for the otel collector/processor\"\n89\t type = string\n90\t default = \"registry.ic-ops.net/cache-docker-hub/otel/opentelemetry-collector-contrib\"\n91\t}\n92\t\n93\tvariable \"otel_lb_replicas\" {\n94\t description = \"number of replicas for the otel loadbalancer to have\"\n95\t type = number\n96\t default = 3\n97\t}\n98\t\n99\tvariable \"otel_collector_replicas\" {\n100\t description = \"number of replicas for the otel collector/processor to have\"\n101\t type = number\n102\t default = 3\n103\t}\n104\t\n105\tvariable \"otel_collector_additional_config\" {\n106\t description = \"Alternate helm chart config to be used (overwrites entire helm config, does not merge)\"\n107\t type = any\n108\t default = null\n109\t}\n110\t"}]},"uuid":"86fda9db-311d-4c5a-8305-2fb27029003c","timestamp":"2026-05-05T19:03:33.285Z","sourceToolAssistantUUID":"0e17e081-a938-4dd4-a4b3-677f867722a0","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"86fda9db-311d-4c5a-8305-2fb27029003c","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01YPWHwVMNnHzKfYNS5x3BgN","type":"message","role":"assistant","content":[{"type":"text","text":"Now I have everything I need. The README is terraform-docs generated format. The structure is:\n1. No title or preamble — starts directly with `## Requirements`\n2. All inputs are in one large alphabetical table\n3. No hand-written narrative sections\n\nI need to:\n1. Add a narrative section before `## Requirements` (or after `## Outputs`) documenting the Vector integration with data-flow, how-to-enable snippet, and variable table\n2. Add the `module_vector` row to the Modules table\n3. Add the 12 `vector_*` variable rows to the Inputs table in alphabetical order\n4. Update the otel-collector module row version (v1.0.7 → v1.1.0)\n\nLet me check the exact format of the module entry for otel_collector in the README and where `vector_*` vars would fall alphabetically:"}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":3521,"cache_read_input_tokens":54756,"cache_creation":{"ephemeral_5m_input_tokens":3521,"ephemeral_1h_input_tokens":0},"output_tokens":2,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwZVAGjndncZ5N7mrTu","attributionAgent":"general-purpose","type":"assistant","uuid":"1a5a7707-1453-43d6-b613-1ead9b08fbb4","timestamp":"2026-05-05T19:03:39.871Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"1a5a7707-1453-43d6-b613-1ead9b08fbb4","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01YPWHwVMNnHzKfYNS5x3BgN","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_01G2SSJygBcW9LFHEQyRz7yH","name":"Bash","input":{"command":"grep -n \"otel_collector\\|module_otel\\|v1.0.7\\|v1.1.0\" \"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md\"","description":"Find otel_collector references in README"},"caller":{"type":"direct"}}],"stop_reason":"tool_use","stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":3521,"cache_read_input_tokens":54756,"output_tokens":344,"server_tool_use":{"web_search_requests":0,"web_fetch_requests":0},"service_tier":"standard","cache_creation":{"ephemeral_1h_input_tokens":0,"ephemeral_5m_input_tokens":3521},"inference_geo":"","iterations":[{"input_tokens":1,"output_tokens":344,"cache_read_input_tokens":54756,"cache_creation_input_tokens":3521,"cache_creation":{"ephemeral_5m_input_tokens":3521,"ephemeral_1h_input_tokens":0},"type":"message"}],"speed":"standard"},"diagnostics":null},"requestId":"req_011CajwZVAGjndncZ5N7mrTu","attributionAgent":"general-purpose","type":"assistant","uuid":"d6458b2b-2c24-4512-8f5f-6eea0b113ff7","timestamp":"2026-05-05T19:03:41.340Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"d6458b2b-2c24-4512-8f5f-6eea0b113ff7","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_01G2SSJygBcW9LFHEQyRz7yH","type":"tool_result","content":"23:| [addon-netpol](#module\\_addon-netpol) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/security/network-policy.git | v1.1.0 |\n37:| [datadog\\_agent](#module\\_datadog\\_agent) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/monitoring/datadog-agent | v1.1.0 |\n50:| [otel\\_collector](#module\\_otel\\_collector) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/monitoring/otel-collector.git | v1.0.7 |\n256:| [otel\\_collector\\_additional\\_config](#input\\_otel\\_collector\\_additional\\_config) | Alternate helm chart config to be used (overwrites entire helm config, does not merge) | `any` | `null` | no |\n257:| [otel\\_collector\\_enabled](#input\\_otel\\_collector\\_enabled) | Override for explicitly enabling or disabling otel-collector | `bool` | `null` | no |\n258:| [otel\\_collector\\_enabled\\_cluster\\_types](#input\\_otel\\_collector\\_enabled\\_cluster\\_types) | Types of clusters otel\\_collector should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": false,
\"infra\": false,
\"mgmt\": true,
\"saas\": true
}
| no |\n259:| [otel\\_collector\\_image\\_tag](#input\\_otel\\_collector\\_image\\_tag) | Version of otel-collector image tag | `string` | `\"\"` | no |\n260:| [otel\\_collector\\_replicas](#input\\_otel\\_collector\\_replicas) | number of replicas for the otel collector/processor to have | `number` | `3` | no |\n261:| [otel\\_collector\\_version](#input\\_otel\\_collector\\_version) | Version of otel-collector helm chart | `string` | `\"\"` | no |","is_error":false}]},"uuid":"1b72b70b-d616-411f-bece-ce9dda4d4f89","timestamp":"2026-05-05T19:03:43.171Z","sourceToolAssistantUUID":"d6458b2b-2c24-4512-8f5f-6eea0b113ff7","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"1b72b70b-d616-411f-bece-ce9dda4d4f89","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_0143ydRLHm72dVwDM27FseyP","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_01QymUHrq9NTfxy754dF1boT","name":"Bash","input":{"command":"grep -n \"wireguard\\|vpc_id\\|## Outputs\" \"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md\"","description":"Find end of inputs table and outputs section"},"caller":{"type":"direct"}}],"stop_reason":"tool_use","stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":1006,"cache_read_input_tokens":58277,"output_tokens":127,"server_tool_use":{"web_search_requests":0,"web_fetch_requests":0},"service_tier":"standard","cache_creation":{"ephemeral_1h_input_tokens":0,"ephemeral_5m_input_tokens":1006},"inference_geo":"","iterations":[{"input_tokens":1,"output_tokens":127,"cache_read_input_tokens":58277,"cache_creation_input_tokens":1006,"cache_creation":{"ephemeral_5m_input_tokens":1006,"ephemeral_1h_input_tokens":0},"type":"message"}],"speed":"standard"},"diagnostics":null},"requestId":"req_011CajwaCt1N8MLqTCRqJFAz","attributionAgent":"general-purpose","type":"assistant","uuid":"bed041e4-12ce-41e2-b3a6-746e9d17ac1c","timestamp":"2026-05-05T19:03:45.440Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"bed041e4-12ce-41e2-b3a6-746e9d17ac1c","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_01QymUHrq9NTfxy754dF1boT","type":"tool_result","content":"319:| [vpc\\_id](#input\\_vpc\\_id) | VPC in which to deploy the cluster | `string` | n/a | yes |\n320:| [wireguard\\_enabled](#input\\_wireguard\\_enabled) | Enables Wireguard Encryption on clusters | `bool` | `true` | no |\n322:## Outputs","is_error":false}]},"uuid":"a7ce072c-cd34-482a-a1a7-6109899ff8f4","timestamp":"2026-05-05T19:03:46.071Z","sourceToolAssistantUUID":"bed041e4-12ce-41e2-b3a6-746e9d17ac1c","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"a7ce072c-cd34-482a-a1a7-6109899ff8f4","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01KbsAVR9YUcpjgBTzhz1WK6","type":"message","role":"assistant","content":[{"type":"text","text":"Now I know where everything is. The `vector_*` variables come alphabetically between `vault_sidecar_injector_version` (line 318) and `vpc_id` (line 319). Let me check what's right before `vpc_id`:"}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":246,"cache_read_input_tokens":59283,"cache_creation":{"ephemeral_5m_input_tokens":246,"ephemeral_1h_input_tokens":0},"output_tokens":3,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwaRH8o26H1bunGVHey","attributionAgent":"general-purpose","type":"assistant","uuid":"52a10a5b-0709-45cd-8434-7c81e8931d59","timestamp":"2026-05-05T19:03:48.852Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"52a10a5b-0709-45cd-8434-7c81e8931d59","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01KbsAVR9YUcpjgBTzhz1WK6","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_019Khu79Y2gcs2Vaxbf488sJ","name":"Read","input":{"file_path":"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md","limit":10,"offset":315},"caller":{"type":"direct"}}],"stop_reason":"tool_use","stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":246,"cache_read_input_tokens":59283,"output_tokens":178,"server_tool_use":{"web_search_requests":0,"web_fetch_requests":0},"service_tier":"standard","cache_creation":{"ephemeral_1h_input_tokens":0,"ephemeral_5m_input_tokens":246},"inference_geo":"","iterations":[{"input_tokens":1,"output_tokens":178,"cache_read_input_tokens":59283,"cache_creation_input_tokens":246,"cache_creation":{"ephemeral_5m_input_tokens":246,"ephemeral_1h_input_tokens":0},"type":"message"}],"speed":"standard"},"diagnostics":null},"requestId":"req_011CajwaRH8o26H1bunGVHey","attributionAgent":"general-purpose","type":"assistant","uuid":"caff3298-9443-4a2a-8ebc-77a2f78b1ba8","timestamp":"2026-05-05T19:03:49.259Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"caff3298-9443-4a2a-8ebc-77a2f78b1ba8","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_019Khu79Y2gcs2Vaxbf488sJ","type":"tool_result","content":"315\t| [vault\\_sidecar\\_injector\\_image\\_tag](#input\\_vault\\_sidecar\\_injector\\_image\\_tag) | Image tag for the vault sidecar injector | `string` | `\"\"` | no |\n316\t| [vault\\_sidecar\\_injector\\_logformat](#input\\_vault\\_sidecar\\_injector\\_logformat) | Logging format for vault sidecar | `string` | `\"json\"` | no |\n317\t| [vault\\_sidecar\\_injector\\_loglevel](#input\\_vault\\_sidecar\\_injector\\_loglevel) | Logging level for vault sidecar | `string` | `\"warn\"` | no |\n318\t| [vault\\_sidecar\\_injector\\_version](#input\\_vault\\_sidecar\\_injector\\_version) | Version of the Vault helm chart, used to deploy the sidecar injector | `string` | `\"\"` | no |\n319\t| [vpc\\_id](#input\\_vpc\\_id) | VPC in which to deploy the cluster | `string` | n/a | yes |\n320\t| [wireguard\\_enabled](#input\\_wireguard\\_enabled) | Enables Wireguard Encryption on clusters | `bool` | `true` | no |\n321\t\n322\t## Outputs\n323\t\n324\t| Name | Description |"}]},"uuid":"2f0ee76a-e671-473f-a547-264cf9f8dc2a","timestamp":"2026-05-05T19:03:49.616Z","sourceToolAssistantUUID":"caff3298-9443-4a2a-8ebc-77a2f78b1ba8","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"2f0ee76a-e671-473f-a547-264cf9f8dc2a","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_011cWGB6zaSH7uLX1A7mEveG","type":"message","role":"assistant","content":[{"type":"text","text":"Now let me check where the module table ends to find the right place to insert `module_vector`. It needs to be alphabetically between `module_vault_sidecar_injector` and... let me check:"}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":613,"cache_read_input_tokens":59529,"cache_creation":{"ephemeral_5m_input_tokens":613,"ephemeral_1h_input_tokens":0},"output_tokens":2,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwagTCaGteVqKYqFF7i","attributionAgent":"general-purpose","type":"assistant","uuid":"620e3125-7ada-4823-a9ee-b47f79630b08","timestamp":"2026-05-05T19:03:52.087Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"620e3125-7ada-4823-a9ee-b47f79630b08","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_011cWGB6zaSH7uLX1A7mEveG","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_01UqXbG3V3Y3E8MibxzR3KJp","name":"Bash","input":{"command":"grep -n \"module_vault\\|module_reloader\\|module_sysdig\\|module_teleport\\|module_s3\" \"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md\"","description":"Find module table entries near vault and end of modules section"},"caller":{"type":"direct"}}],"stop_reason":"tool_use","stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":613,"cache_read_input_tokens":59529,"output_tokens":192,"server_tool_use":{"web_search_requests":0,"web_fetch_requests":0},"service_tier":"standard","cache_creation":{"ephemeral_1h_input_tokens":0,"ephemeral_5m_input_tokens":613},"inference_geo":"","iterations":[{"input_tokens":1,"output_tokens":192,"cache_read_input_tokens":59529,"cache_creation_input_tokens":613,"cache_creation":{"ephemeral_5m_input_tokens":613,"ephemeral_1h_input_tokens":0},"type":"message"}],"speed":"standard"},"diagnostics":null},"requestId":"req_011CajwagTCaGteVqKYqFF7i","attributionAgent":"general-purpose","type":"assistant","uuid":"a0380062-adb0-408a-96cb-314668abdab6","timestamp":"2026-05-05T19:03:53.082Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"a0380062-adb0-408a-96cb-314668abdab6","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_01UqXbG3V3Y3E8MibxzR3KJp","type":"tool_result","content":"51:| [reloader](#module\\_reloader) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/compute/reloader.git | v1.0.1 |\n52:| [s3\\_csi\\_driver](#module\\_s3\\_csi\\_driver) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/storage/s3-csi-driver.git | v1.1.1 |\n53:| [s3\\_csi\\_driver\\_sa](#module\\_s3\\_csi\\_driver\\_sa) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/aws/security/kubernetes-iam-serviceaccount.git | v7.0.0 |\n54:| [sysdig\\_agent](#module\\_sysdig\\_agent) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/security/sysdig-agent.git | v4.0.0 |\n55:| [teleport](#module\\_teleport) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/security/teleport-agent.git | v3.0.0 |\n56:| [teleport\\_agent\\_sa](#module\\_teleport\\_agent\\_sa) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/aws/security/kubernetes-iam-serviceaccount.git | v7.0.0 |\n57:| [vault\\_sidecar\\_injector](#module\\_vault\\_sidecar\\_injector) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/security/vault-sidecar-injector.git | v4.1.0 |","is_error":false}]},"uuid":"5f885bba-7667-4b8f-8ba4-84a3438bcb25","timestamp":"2026-05-05T19:03:53.686Z","sourceToolAssistantUUID":"a0380062-adb0-408a-96cb-314668abdab6","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"5f885bba-7667-4b8f-8ba4-84a3438bcb25","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01Xrpv7Lh4GbCxbSeCq7EeVu","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_01KnAwKxN8hV5zQr64uVoRJz","name":"Read","input":{"file_path":"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md","limit":10,"offset":57},"caller":{"type":"direct"}}],"stop_reason":"tool_use","stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":733,"cache_read_input_tokens":60142,"output_tokens":119,"server_tool_use":{"web_search_requests":0,"web_fetch_requests":0},"service_tier":"standard","cache_creation":{"ephemeral_1h_input_tokens":0,"ephemeral_5m_input_tokens":733},"inference_geo":"","iterations":[{"input_tokens":1,"output_tokens":119,"cache_read_input_tokens":60142,"cache_creation_input_tokens":733,"cache_creation":{"ephemeral_5m_input_tokens":733,"ephemeral_1h_input_tokens":0},"type":"message"}],"speed":"standard"},"diagnostics":null},"requestId":"req_011Cajwaz3NPYUUNJmGrNtpe","attributionAgent":"general-purpose","type":"assistant","uuid":"4c2140ec-df33-491b-afd3-9ddd9af9aaf2","timestamp":"2026-05-05T19:03:55.877Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"4c2140ec-df33-491b-afd3-9ddd9af9aaf2","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_01KnAwKxN8hV5zQr64uVoRJz","type":"tool_result","content":"57\t| [vault\\_sidecar\\_injector](#module\\_vault\\_sidecar\\_injector) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/security/vault-sidecar-injector.git | v4.1.0 |\n58\t\n59\t## Resources\n60\t\n61\t| Name | Type |\n62\t|------|------|\n63\t| [aws_eks_addon.aws_ebs_csi_driver](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/eks_addon) | resource |\n64\t| [aws_eks_addon.kube_proxy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/eks_addon) | resource |\n65\t| [aws_iam_role_policy_attachment.ebs_csi_policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role_policy_attachment) | resource |\n66\t| [aws_vpc_security_group_ingress_rule.cluster_mesh_cidrs](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/vpc_security_group_ingress_rule) | resource |"}]},"uuid":"e27bd74e-3638-400e-a95d-eced7ac60948","timestamp":"2026-05-05T19:03:56.164Z","sourceToolAssistantUUID":"4c2140ec-df33-491b-afd3-9ddd9af9aaf2","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"e27bd74e-3638-400e-a95d-eced7ac60948","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01VU7UVCx2sAfGLv379KByEa","type":"message","role":"assistant","content":[{"type":"text","text":"Good. `vector` comes after `vault_sidecar_injector` alphabetically (`ve` > `va`). So `module_vector` goes after line 57 (the vault_sidecar_injector module row), before the blank line at line 58.\n\nNow I have a complete picture. Let me plan all the changes:\n\n1. **Add narrative section** before `## Requirements` (at the start of the file, line 0) — a `## Vector (telemetry redaction aggregator)` section covering data-flow, how-to-enable, and cross-link to spec.\n\n2. **Add `module_vector` row** after line 57 (vault_sidecar_injector), alphabetically correct.\n\n3. **Update `module_otel_collector` version** from `v1.0.7` to `v1.1.0` on line 50.\n\n4. **Add 12 `vector_*` input rows** between `vault_sidecar_injector_version` (line 318) and `vpc_id` (line 319).\n\nLet me now make all the changes:"}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":456,"cache_read_input_tokens":60875,"cache_creation":{"ephemeral_5m_input_tokens":456,"ephemeral_1h_input_tokens":0},"output_tokens":3,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwbAVAnrSVq589BdqhC","attributionAgent":"general-purpose","type":"assistant","uuid":"ed2c17d6-f176-4512-bac2-be29634625c9","timestamp":"2026-05-05T19:04:02.166Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"ed2c17d6-f176-4512-bac2-be29634625c9","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01VU7UVCx2sAfGLv379KByEa","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_01WYDwMwxdfvXUAnj4ecm54s","name":"Edit","input":{"replace_all":false,"file_path":"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md","old_string":"## Requirements","new_string":"## Vector (telemetry redaction aggregator)\n\nVector is an optional in-cluster aggregator that sits between the OTel collector and Datadog. When enabled it applies VRL-based transforms — dropping audit log lines and redacting email addresses — across logs, traces, and metrics before shipping to Datadog. See the [design spec](../../../../docs/superpowers/specs/2026-05-05-vector-redaction-design.md) for full architecture, failure-mode analysis, and rollout guidance.\n\n### Data flow\n\nWhen `vector_enabled = true`:\n\n```\napps → otel-lb → otel-collector → vector → Datadog\n```\n\nThe otel-collector's terminal exporter switches from `datadog` to `otlp` (gRPC pointed at `vector.vector.svc.cluster.local:4317`). The Datadog API key ownership moves from the otel-collector to the Vector module's ExternalSecret. The otel-collector module is pinned to `v1.1.0` which introduced the `downstream_endpoint` variable; `v1.0.7` and earlier are not compatible with this mode.\n\nWhen `vector_enabled = false` (or unset and the cluster type defaults to disabled):\n\n```\napps → otel-lb → otel-collector → Datadog\n```\n\nThe `otel-collector` module reverts to its original `datadog` exporter. No Vector resources are created.\n\n### Enabling Vector for a cluster\n\nThe five required variables must be set together with `vector_enabled = true`. The remaining variables have defaults that are suitable for most clusters.\n\n```hcl\nvector_enabled = true\nvector_chart_version = \"0.36.0\"\nvector_image_tag = \"0.40.0-distroless-libc\"\nvector_datadog_site = \"datadoghq.com\"\nvector_datadog_api_key_vault_path = \"secret/data/datadog/api-key\"\nvector_external_secrets_cluster_store_name = \"vault-cluster-store\"\n```\n\nVector requires `external_secrets_enabled = true` (or a cluster type that enables it by default). A Terraform validation block enforces this dependency.\n\n### Vector variables\n\n| Variable | Description | Type | Default | Required when enabled |\n|---|---|---|---|---|\n| `vector_chart_version` | Vector helm chart version pin | `string` | `\"\"` | yes |\n| `vector_image_tag` | Vector image tag | `string` | `\"\"` | yes |\n| `vector_datadog_site` | Datadog site for Vector sinks (e.g. `datadoghq.com`) | `string` | `\"\"` | yes |\n| `vector_datadog_api_key_vault_path` | Vault path for the Datadog API key consumed by Vector's ExternalSecret | `string` | `\"\"` | yes |\n| `vector_external_secrets_cluster_store_name` | Name of the ClusterSecretStore created by the external-secrets module | `string` | `\"\"` | yes |\n| `vector_enabled` | Override for explicitly enabling or disabling Vector | `bool` | `null` | no |\n| `vector_enabled_cluster_types` | Per-cluster-type defaults (`mgmt/cps/saas=true`, `infra/dev=false`) | `map(bool)` | see below | no |\n| `vector_image` | Vector container image (registry/path) | `string` | `registry.ic-ops.net/cache-docker-hub/timberio/vector` | no |\n| `vector_replicas` | Number of Vector aggregator replicas | `number` | `3` | no |\n| `vector_audit_drop_patterns` | Regex patterns; matching log message bodies are dropped before Datadog | `list(string)` | Immuta audit patterns | no |\n| `vector_email_redaction_enabled` | Toggle the email-redact VRL transform across all three signals | `bool` | `true` | no |\n| `vector_email_redaction_replacement` | Replacement string for redacted email addresses | `string` | `[REDACTED-EMAIL]` | no |\n| `vector_additional_config` | Escape-hatch: overwrites the entire Vector `customConfig` helm value | `any` | `null` | no |\n\n---\n\n## Requirements"},"caller":{"type":"direct"}}],"stop_reason":"tool_use","stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":456,"cache_read_input_tokens":60875,"output_tokens":1416,"server_tool_use":{"web_search_requests":0,"web_fetch_requests":0},"service_tier":"standard","cache_creation":{"ephemeral_1h_input_tokens":0,"ephemeral_5m_input_tokens":456},"inference_geo":"","iterations":[{"input_tokens":1,"output_tokens":1416,"cache_read_input_tokens":60875,"cache_creation_input_tokens":456,"cache_creation":{"ephemeral_5m_input_tokens":456,"ephemeral_1h_input_tokens":0},"type":"message"}],"speed":"standard"},"diagnostics":null},"requestId":"req_011CajwbAVAnrSVq589BdqhC","attributionAgent":"general-purpose","type":"assistant","uuid":"a3da8e5c-8640-4847-9103-d4c21a8aa751","timestamp":"2026-05-05T19:04:20.231Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"a3da8e5c-8640-4847-9103-d4c21a8aa751","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_01WYDwMwxdfvXUAnj4ecm54s","type":"tool_result","content":"The file /Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md has been updated successfully. (file state is current in your context — no need to Read it back)"}]},"uuid":"b4b79855-164a-4de0-a271-c2c0bd7ac36a","timestamp":"2026-05-05T19:04:30.156Z","sourceToolAssistantUUID":"a3da8e5c-8640-4847-9103-d4c21a8aa751","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"b4b79855-164a-4de0-a271-c2c0bd7ac36a","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_012NXzz43DmcaEgzZbHpJNwS","type":"message","role":"assistant","content":[{"type":"text","text":"Now update the otel_collector module version from v1.0.7 to v1.1.0:"}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":1502,"cache_read_input_tokens":61331,"cache_creation":{"ephemeral_5m_input_tokens":1502,"ephemeral_1h_input_tokens":0},"output_tokens":6,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwdfundWJAa9UxW8keZ","attributionAgent":"general-purpose","type":"assistant","uuid":"8e40a945-6b9b-4142-8eb1-eeb49b36d663","timestamp":"2026-05-05T19:04:32.125Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"8e40a945-6b9b-4142-8eb1-eeb49b36d663","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_012NXzz43DmcaEgzZbHpJNwS","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_01NC9nerowAZoXwiXdYbxzEu","name":"Edit","input":{"replace_all":false,"file_path":"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md","old_string":"| [otel\\_collector](#module\\_otel\\_collector) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/monitoring/otel-collector.git | v1.0.7 |","new_string":"| [otel\\_collector](#module\\_otel\\_collector) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/monitoring/otel-collector.git | v1.1.0 |"},"caller":{"type":"direct"}}],"stop_reason":"tool_use","stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":1502,"cache_read_input_tokens":61331,"output_tokens":279,"server_tool_use":{"web_search_requests":0,"web_fetch_requests":0},"service_tier":"standard","cache_creation":{"ephemeral_1h_input_tokens":0,"ephemeral_5m_input_tokens":1502},"inference_geo":"","iterations":[{"input_tokens":1,"output_tokens":279,"cache_read_input_tokens":61331,"cache_creation_input_tokens":1502,"cache_creation":{"ephemeral_5m_input_tokens":1502,"ephemeral_1h_input_tokens":0},"type":"message"}],"speed":"standard"},"diagnostics":null},"requestId":"req_011CajwdfundWJAa9UxW8keZ","attributionAgent":"general-purpose","type":"assistant","uuid":"4683c911-8fec-4f59-b444-3b04b5d8c69e","timestamp":"2026-05-05T19:04:33.616Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"4683c911-8fec-4f59-b444-3b04b5d8c69e","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_01NC9nerowAZoXwiXdYbxzEu","type":"tool_result","content":"The file /Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md has been updated successfully. (file state is current in your context — no need to Read it back)"}]},"uuid":"5615c592-455a-4575-9020-bc939c4eecee","timestamp":"2026-05-05T19:07:36.142Z","sourceToolAssistantUUID":"4683c911-8fec-4f59-b444-3b04b5d8c69e","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"5615c592-455a-4575-9020-bc939c4eecee","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01FY1HFcqZ5Fj752MZCCF3JG","type":"message","role":"assistant","content":[{"type":"text","text":"Now add the `module_vector` row after `module_vault_sidecar_injector`:"}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":365,"cache_read_input_tokens":62833,"cache_creation":{"ephemeral_5m_input_tokens":365,"ephemeral_1h_input_tokens":0},"output_tokens":4,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwsPCqjhNwReufZRWJ7","attributionAgent":"general-purpose","type":"assistant","uuid":"db6ea595-a851-4ee9-adef-7fc727509b8c","timestamp":"2026-05-05T19:07:38.573Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"db6ea595-a851-4ee9-adef-7fc727509b8c","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01FY1HFcqZ5Fj752MZCCF3JG","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_01JKDKVZqLYvG8YkVLP2ZMBr","name":"Edit","input":{"replace_all":false,"file_path":"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md","old_string":"| [vault\\_sidecar\\_injector](#module\\_vault\\_sidecar\\_injector) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/security/vault-sidecar-injector.git | v4.1.0 |\n\n## Resources","new_string":"| [vault\\_sidecar\\_injector](#module\\_vault\\_sidecar\\_injector) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/security/vault-sidecar-injector.git | v4.1.0 |\n| [vector](#module\\_vector) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/monitoring/vector.git | v1.0.0 |\n\n## Resources"},"caller":{"type":"direct"}}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":365,"cache_read_input_tokens":62833,"cache_creation":{"ephemeral_5m_input_tokens":365,"ephemeral_1h_input_tokens":0},"output_tokens":4,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwsPCqjhNwReufZRWJ7","attributionAgent":"general-purpose","type":"assistant","uuid":"a72859d7-72ed-4b5d-8a4e-da0dec8134a7","timestamp":"2026-05-05T19:07:40.774Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"a72859d7-72ed-4b5d-8a4e-da0dec8134a7","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_01JKDKVZqLYvG8YkVLP2ZMBr","type":"tool_result","content":"The file /Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md has been updated successfully. (file state is current in your context — no need to Read it back)"}]},"uuid":"7e6714d1-8201-4776-a867-97b76331e339","timestamp":"2026-05-05T19:08:33.298Z","sourceToolAssistantUUID":"a72859d7-72ed-4b5d-8a4e-da0dec8134a7","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"7e6714d1-8201-4776-a867-97b76331e339","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_017JqEPwYJWWduYZ6x4ptoZN","type":"message","role":"assistant","content":[{"type":"text","text":"Now add the 12 `vector_*` input rows. They go between `vault_sidecar_injector_version` and `vpc_id`. Let me construct the rows in alphabetical order:\n\n- `vector_additional_config` (va < vc... actually `vector_a` < `vector_c` < `vector_d` < `vector_e` (x2) < `vector_i` < `vector_r` < `vector_enabled`, `vector_enabled_cluster_types`... let me sort properly)\n\nAlphabetical order of the 12 variables:\n1. `vector_additional_config`\n2. `vector_audit_drop_patterns`\n3. `vector_chart_version`\n4. `vector_datadog_api_key_vault_path`\n5. `vector_datadog_site`\n6. `vector_email_redaction_enabled`\n7. `vector_email_redaction_replacement`\n8. `vector_enabled`\n9. `vector_enabled_cluster_types`\n10. `vector_external_secrets_cluster_store_name`\n11. `vector_image`\n12. `vector_image_tag`\n13. `vector_replicas`\n\nWait, that's 13. Let me re-count from the task: the task lists 12+1=13 variables. The task says \"12 new variables\" but lists 13. Let me count from the actual `vector.tf`:\n1. `vector_chart_version`\n2. `vector_image_tag`\n3. `vector_datadog_site`\n4. `vector_datadog_api_key_vault_path`\n5. `vector_external_secrets_cluster_store_name`\n6. `vector_enabled_cluster_types`\n7. `vector_enabled`\n8. `vector_image`\n9. `vector_replicas`\n10. `vector_audit_drop_patterns`\n11. `vector_email_redaction_enabled`\n12. `vector_email_redaction_replacement`\n13. `vector_additional_config`\n\nThat's 13 variables. The task description says 12 but the task context lists 13 (including `vector_external_secrets_cluster_store_name`). I'll document all 13.\n\nAlphabetical sort:\n1. `vector_additional_config`\n2. `vector_audit_drop_patterns`\n3. `vector_chart_version`\n4. `vector_datadog_api_key_vault_path`\n5. `vector_datadog_site`\n6. `vector_email_redaction_enabled`\n7. `vector_email_redaction_replacement`\n8. `vector_enabled`\n9. `vector_enabled_cluster_types`\n10. `vector_external_secrets_cluster_store_name`\n11. `vector_image`\n12. `vector_image_tag`\n13. `vector_replicas`\n\nNow I need to format these exactly like the existing input rows. The default for `vector_enabled_cluster_types` is a map with 5 entries. Let me look at a comparable map default to get the exact format:\n\nLooking at `otel_collector_enabled_cluster_types` (line 258):\n```\n`map(string)` |
{
\"cps\": true,
\"dev\": false,
\"infra\": false,
\"mgmt\": true,
\"saas\": true
}
\n```\n\nNote: the vector type is `map(string)` in the README even though the actual type is `map(bool)` — the README uses `map(string)` for all such defaults. I'll match the existing convention: use `map(string)` to be consistent with the existing pattern (though technically `map(bool)` is correct). Actually looking at the README, `application_deployment_enabled_cluster_types` uses `map(bool)` at line 88. Let me check — yes it shows `map(bool)`. For `vector_enabled_cluster_types` the actual type is `map(string)` per the vector.tf file (line 113: `type = map(string)`). So I'll use `map(string)`.\n\nFor `vector_audit_drop_patterns`, the default is a list of two strings. Looking at `cluster_mesh_tls_names` or similar for a list default format:\n```\n`list(string)` | `[]` | no\n```\nBut we have non-empty defaults. Looking at how other lists with values are shown... Actually the file doesn't seem to have a list with a non-empty default other than `kyverno_cluster_role_rules`. I'll use `
` format for the list.\n\nThe `vector_email_redaction_replacement` default `[REDACTED-EMAIL]` contains brackets — in the table it should be escaped or wrapped. I'll wrap it in backticks within the cell.\n\nLet me now construct the rows:"}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":455,"cache_read_input_tokens":63198,"cache_creation":{"ephemeral_5m_input_tokens":455,"ephemeral_1h_input_tokens":0},"output_tokens":2,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwwowF2QNY9svcFe77j","attributionAgent":"general-purpose","type":"assistant","uuid":"5dde942d-596f-4b96-8f31-5f561289f362","timestamp":"2026-05-05T19:08:53.710Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"}
{"parentUuid":"5dde942d-596f-4b96-8f31-5f561289f362","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_017JqEPwYJWWduYZ6x4ptoZN","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_012Bwwtgu8pnaLwkSrhiSs9N","name":"Edit","input":{"replace_all":false,"file_path":"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md","old_string":"|  [vault\\_sidecar\\_injector\\_version](#input\\_vault\\_sidecar\\_injector\\_version) | Version of the Vault helm chart, used to deploy the sidecar injector | `string` | `\"\"` | no |\n|  [vpc\\_id](#input\\_vpc\\_id) | VPC in which to deploy the cluster | `string` | n/a | yes |","new_string":"|  [vault\\_sidecar\\_injector\\_version](#input\\_vault\\_sidecar\\_injector\\_version) | Version of the Vault helm chart, used to deploy the sidecar injector | `string` | `\"\"` | no |\n|  [vector\\_additional\\_config](#input\\_vector\\_additional\\_config) | Alternate helm chart customConfig for Vector (overwrites entire helm config, does not merge) | `any` | `null` | no |\n|  [vector\\_audit\\_drop\\_patterns](#input\\_vector\\_audit\\_drop\\_patterns) | Regex patterns; log message bodies matching any pattern are dropped before Datadog | `list(string)` | 
[
\"Audit\\\\s-\\\\s.+\",
\"\\\"level\\\":\\\"audit\\\"\"
]
| no |\n| [vector\\_chart\\_version](#input\\_vector\\_chart\\_version) | Version of Vector helm chart | `string` | `\"\"` | no |\n| [vector\\_datadog\\_api\\_key\\_vault\\_path](#input\\_vector\\_datadog\\_api\\_key\\_vault\\_path) | Vault path for the Datadog API key consumed by Vector's ExternalSecret | `string` | `\"\"` | no |\n| [vector\\_datadog\\_site](#input\\_vector\\_datadog\\_site) | Datadog site for Vector sinks (e.g. `datadoghq.com`) | `string` | `\"\"` | no |\n| [vector\\_email\\_redaction\\_enabled](#input\\_vector\\_email\\_redaction\\_enabled) | Toggle the email-redact VRL transform across logs, traces, and metrics | `bool` | `true` | no |\n| [vector\\_email\\_redaction\\_replacement](#input\\_vector\\_email\\_redaction\\_replacement) | String that replaces matched email addresses | `string` | `\"[REDACTED-EMAIL]\"` | no |\n| [vector\\_enabled](#input\\_vector\\_enabled) | Override for explicitly enabling or disabling Vector | `bool` | `null` | no |\n| [vector\\_enabled\\_cluster\\_types](#input\\_vector\\_enabled\\_cluster\\_types) | Types of clusters Vector should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": false,
\"infra\": false,
\"mgmt\": true,
\"saas\": true
}
| no |\n| [vector\\_external\\_secrets\\_cluster\\_store\\_name](#input\\_vector\\_external\\_secrets\\_cluster\\_store\\_name) | Name of the ClusterSecretStore (created by the external-secrets module) used by Vector's ExternalSecret. Required when Vector is enabled. | `string` | `\"\"` | no |\n| [vector\\_image](#input\\_vector\\_image) | Image for the Vector aggregator | `string` | `\"registry.ic-ops.net/cache-docker-hub/timberio/vector\"` | no |\n| [vector\\_image\\_tag](#input\\_vector\\_image\\_tag) | Vector image tag | `string` | `\"\"` | no |\n| [vector\\_replicas](#input\\_vector\\_replicas) | Number of Vector aggregator replicas | `number` | `3` | no |\n| [vpc\\_id](#input\\_vpc\\_id) | VPC in which to deploy the cluster | `string` | n/a | yes |"},"caller":{"type":"direct"}}],"stop_reason":"tool_use","stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":455,"cache_read_input_tokens":63198,"output_tokens":2448,"server_tool_use":{"web_search_requests":0,"web_fetch_requests":0},"service_tier":"standard","cache_creation":{"ephemeral_1h_input_tokens":0,"ephemeral_5m_input_tokens":455},"inference_geo":"","iterations":[{"input_tokens":1,"output_tokens":2448,"cache_read_input_tokens":63198,"cache_creation_input_tokens":455,"cache_creation":{"ephemeral_5m_input_tokens":455,"ephemeral_1h_input_tokens":0},"type":"message"}],"speed":"standard"},"diagnostics":null},"requestId":"req_011CajwwowF2QNY9svcFe77j","attributionAgent":"general-purpose","type":"assistant","uuid":"da0baf2e-d58d-4178-817a-bc3ed65e5422","timestamp":"2026-05-05T19:09:04.105Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"da0baf2e-d58d-4178-817a-bc3ed65e5422","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_012Bwwtgu8pnaLwkSrhiSs9N","type":"tool_result","content":"The file /Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md has been updated successfully. (file state is current in your context — no need to Read it back)"}]},"uuid":"b83aeb30-71ed-4cb9-a9a8-4a1dc0b8c0ef","timestamp":"2026-05-05T19:09:08.106Z","sourceToolAssistantUUID":"da0baf2e-d58d-4178-817a-bc3ed65e5422","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"b83aeb30-71ed-4cb9-a9a8-4a1dc0b8c0ef","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_017WRfYuMUKWRvuCEawQ4Tc4","type":"message","role":"assistant","content":[{"type":"text","text":"Now let me verify all the changes look correct:"}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":2515,"cache_read_input_tokens":63653,"cache_creation":{"ephemeral_5m_input_tokens":2515,"ephemeral_1h_input_tokens":0},"output_tokens":2,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwzAaXHMBtpSTygRbKj","attributionAgent":"general-purpose","type":"assistant","uuid":"224a9ea6-ffa9-4950-bcc5-82cfa7d8c935","timestamp":"2026-05-05T19:09:09.883Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"224a9ea6-ffa9-4950-bcc5-82cfa7d8c935","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_017WRfYuMUKWRvuCEawQ4Tc4","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_01KZeeFL1jMbvK8FQoJqaTTf","name":"Bash","input":{"command":"grep -n \"vector\\|Vector\\|otel_collector.*v1\\.\" \"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md\" | head -60","description":"Verify all vector and otel_collector references in README"},"caller":{"type":"direct"}}],"stop_reason":"tool_use","stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":2515,"cache_read_input_tokens":63653,"output_tokens":147,"server_tool_use":{"web_search_requests":0,"web_fetch_requests":0},"service_tier":"standard","cache_creation":{"ephemeral_1h_input_tokens":0,"ephemeral_5m_input_tokens":2515},"inference_geo":"","iterations":[{"input_tokens":1,"output_tokens":147,"cache_read_input_tokens":63653,"cache_creation_input_tokens":2515,"cache_creation":{"ephemeral_5m_input_tokens":2515,"ephemeral_1h_input_tokens":0},"type":"message"}],"speed":"standard"},"diagnostics":null},"requestId":"req_011CajwzAaXHMBtpSTygRbKj","attributionAgent":"general-purpose","type":"assistant","uuid":"1558731d-064a-4249-aea9-fa2746288c1e","timestamp":"2026-05-05T19:09:10.895Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"1558731d-064a-4249-aea9-fa2746288c1e","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_01KZeeFL1jMbvK8FQoJqaTTf","type":"tool_result","content":"1:## Vector (telemetry redaction aggregator)\n3:Vector is an optional in-cluster aggregator that sits between the OTel collector and Datadog. When enabled it applies VRL-based transforms — dropping audit log lines and redacting email addresses — across logs, traces, and metrics before shipping to Datadog. See the [design spec](../../../../docs/superpowers/specs/2026-05-05-vector-redaction-design.md) for full architecture, failure-mode analysis, and rollout guidance.\n7:When `vector_enabled = true`:\n10:apps → otel-lb → otel-collector → vector → Datadog\n13:The otel-collector's terminal exporter switches from `datadog` to `otlp` (gRPC pointed at `vector.vector.svc.cluster.local:4317`). The Datadog API key ownership moves from the otel-collector to the Vector module's ExternalSecret. The otel-collector module is pinned to `v1.1.0` which introduced the `downstream_endpoint` variable; `v1.0.7` and earlier are not compatible with this mode.\n15:When `vector_enabled = false` (or unset and the cluster type defaults to disabled):\n21:The `otel-collector` module reverts to its original `datadog` exporter. No Vector resources are created.\n23:### Enabling Vector for a cluster\n25:The five required variables must be set together with `vector_enabled = true`. The remaining variables have defaults that are suitable for most clusters.\n28:vector_enabled = true\n29:vector_chart_version = \"0.36.0\"\n30:vector_image_tag = \"0.40.0-distroless-libc\"\n31:vector_datadog_site = \"datadoghq.com\"\n32:vector_datadog_api_key_vault_path = \"secret/data/datadog/api-key\"\n33:vector_external_secrets_cluster_store_name = \"vault-cluster-store\"\n36:Vector requires `external_secrets_enabled = true` (or a cluster type that enables it by default). A Terraform validation block enforces this dependency.\n38:### Vector variables\n42:| `vector_chart_version` | Vector helm chart version pin | `string` | `\"\"` | yes |\n43:| `vector_image_tag` | Vector image tag | `string` | `\"\"` | yes |\n44:| `vector_datadog_site` | Datadog site for Vector sinks (e.g. `datadoghq.com`) | `string` | `\"\"` | yes |\n45:| `vector_datadog_api_key_vault_path` | Vault path for the Datadog API key consumed by Vector's ExternalSecret | `string` | `\"\"` | yes |\n46:| `vector_external_secrets_cluster_store_name` | Name of the ClusterSecretStore created by the external-secrets module | `string` | `\"\"` | yes |\n47:| `vector_enabled` | Override for explicitly enabling or disabling Vector | `bool` | `null` | no |\n48:| `vector_enabled_cluster_types` | Per-cluster-type defaults (`mgmt/cps/saas=true`, `infra/dev=false`) | `map(bool)` | see below | no |\n49:| `vector_image` | Vector container image (registry/path) | `string` | `registry.ic-ops.net/cache-docker-hub/timberio/vector` | no |\n50:| `vector_replicas` | Number of Vector aggregator replicas | `number` | `3` | no |\n51:| `vector_audit_drop_patterns` | Regex patterns; matching log message bodies are dropped before Datadog | `list(string)` | Immuta audit patterns | no |\n52:| `vector_email_redaction_enabled` | Toggle the email-redact VRL transform across all three signals | `bool` | `true` | no |\n53:| `vector_email_redaction_replacement` | Replacement string for redacted email addresses | `string` | `[REDACTED-EMAIL]` | no |\n54:| `vector_additional_config` | Escape-hatch: overwrites the entire Vector `customConfig` helm value | `any` | `null` | no |\n107:| [otel\\_collector](#module\\_otel\\_collector) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/monitoring/otel-collector.git | v1.1.0 |\n115:| [vector](#module\\_vector) | git@gitlab.infrastructure.immuta.io:infrastructure/terraform/internal-modules/kubernetes/monitoring/vector.git | v1.0.0 |\n377:| [vector\\_additional\\_config](#input\\_vector\\_additional\\_config) | Alternate helm chart customConfig for Vector (overwrites entire helm config, does not merge) | `any` | `null` | no |\n378:| [vector\\_audit\\_drop\\_patterns](#input\\_vector\\_audit\\_drop\\_patterns) | Regex patterns; log message bodies matching any pattern are dropped before Datadog | `list(string)` |
[
\"Audit\\\\s-\\\\s.+\",
\"\\\"level\\\":\\\"audit\\\"\"
]
| no |\n379:| [vector\\_chart\\_version](#input\\_vector\\_chart\\_version) | Version of Vector helm chart | `string` | `\"\"` | no |\n380:| [vector\\_datadog\\_api\\_key\\_vault\\_path](#input\\_vector\\_datadog\\_api\\_key\\_vault\\_path) | Vault path for the Datadog API key consumed by Vector's ExternalSecret | `string` | `\"\"` | no |\n381:| [vector\\_datadog\\_site](#input\\_vector\\_datadog\\_site) | Datadog site for Vector sinks (e.g. `datadoghq.com`) | `string` | `\"\"` | no |\n382:| [vector\\_email\\_redaction\\_enabled](#input\\_vector\\_email\\_redaction\\_enabled) | Toggle the email-redact VRL transform across logs, traces, and metrics | `bool` | `true` | no |\n383:| [vector\\_email\\_redaction\\_replacement](#input\\_vector\\_email\\_redaction\\_replacement) | String that replaces matched email addresses | `string` | `\"[REDACTED-EMAIL]\"` | no |\n384:| [vector\\_enabled](#input\\_vector\\_enabled) | Override for explicitly enabling or disabling Vector | `bool` | `null` | no |\n385:| [vector\\_enabled\\_cluster\\_types](#input\\_vector\\_enabled\\_cluster\\_types) | Types of clusters Vector should be enabled on by default | `map(string)` |
{
\"cps\": true,
\"dev\": false,
\"infra\": false,
\"mgmt\": true,
\"saas\": true
}
| no |\n386:| [vector\\_external\\_secrets\\_cluster\\_store\\_name](#input\\_vector\\_external\\_secrets\\_cluster\\_store\\_name) | Name of the ClusterSecretStore (created by the external-secrets module) used by Vector's ExternalSecret. Required when Vector is enabled. | `string` | `\"\"` | no |\n387:| [vector\\_image](#input\\_vector\\_image) | Image for the Vector aggregator | `string` | `\"registry.ic-ops.net/cache-docker-hub/timberio/vector\"` | no |\n388:| [vector\\_image\\_tag](#input\\_vector\\_image\\_tag) | Vector image tag | `string` | `\"\"` | no |\n389:| [vector\\_replicas](#input\\_vector\\_replicas) | Number of Vector aggregator replicas | `number` | `3` | no |","is_error":false}]},"uuid":"5924d9d9-c6a0-4238-a331-d88cf07112a5","timestamp":"2026-05-05T19:09:12.821Z","sourceToolAssistantUUID":"1558731d-064a-4249-aea9-fa2746288c1e","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"5924d9d9-c6a0-4238-a331-d88cf07112a5","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_017kn6juyKmXiTPpuBvZhsU6","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_01QZrbTB66deQQM2c3raVCSY","name":"Bash","input":{"command":"wc -l \"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md\"","description":"Count final line count"},"caller":{"type":"direct"}}],"stop_reason":"tool_use","stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":2249,"cache_read_input_tokens":66168,"output_tokens":109,"server_tool_use":{"web_search_requests":0,"web_fetch_requests":0},"service_tier":"standard","cache_creation":{"ephemeral_1h_input_tokens":0,"ephemeral_5m_input_tokens":2249},"inference_geo":"","iterations":[{"input_tokens":1,"output_tokens":109,"cache_read_input_tokens":66168,"cache_creation_input_tokens":2249,"cache_creation":{"ephemeral_5m_input_tokens":2249,"ephemeral_1h_input_tokens":0},"type":"message"}],"speed":"standard"},"diagnostics":null},"requestId":"req_011CajwzWLumoGiJx74XUU9v","attributionAgent":"general-purpose","type":"assistant","uuid":"e4d83844-16fa-4056-8f79-b783eb372a66","timestamp":"2026-05-05T19:09:15.323Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"e4d83844-16fa-4056-8f79-b783eb372a66","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_01QZrbTB66deQQM2c3raVCSY","type":"tool_result","content":" 397 /Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md","is_error":false}]},"uuid":"536989bd-66bf-473e-b25f-0fb6e7b5ec9f","timestamp":"2026-05-05T19:09:15.670Z","sourceToolAssistantUUID":"e4d83844-16fa-4056-8f79-b783eb372a66","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"536989bd-66bf-473e-b25f-0fb6e7b5ec9f","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01D8DNNK47kzaCFvJZxAAjY5","type":"message","role":"assistant","content":[{"type":"text","text":"All changes are in place. Let me do a final verification pass:"}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":2406,"cache_read_input_tokens":66168,"cache_creation":{"ephemeral_5m_input_tokens":2406,"ephemeral_1h_input_tokens":0},"output_tokens":1,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwziTB6YJzPW3MTmrQ5","attributionAgent":"general-purpose","type":"assistant","uuid":"8d0ef0a6-2e92-4579-9b4d-0f6804ae57ba","timestamp":"2026-05-05T19:09:17.576Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"8d0ef0a6-2e92-4579-9b4d-0f6804ae57ba","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01D8DNNK47kzaCFvJZxAAjY5","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_01GGmVbx76735zSpRHFwdJrC","name":"Bash","input":{"command":"grep -c \"vector_\" \"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md\"","description":"Count total vector_ references"},"caller":{"type":"direct"}}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":2406,"cache_read_input_tokens":66168,"cache_creation":{"ephemeral_5m_input_tokens":2406,"ephemeral_1h_input_tokens":0},"output_tokens":1,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwziTB6YJzPW3MTmrQ5","attributionAgent":"general-purpose","type":"assistant","uuid":"2f238d38-27d2-4632-89da-1552b7f61485","timestamp":"2026-05-05T19:09:18.412Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"2f238d38-27d2-4632-89da-1552b7f61485","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_01GGmVbx76735zSpRHFwdJrC","type":"tool_result","content":"35","is_error":false}]},"uuid":"1ad1f0c7-64bc-4732-87e2-a4276f6b2d5b","timestamp":"2026-05-05T19:09:19.066Z","sourceToolAssistantUUID":"2f238d38-27d2-4632-89da-1552b7f61485","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"1ad1f0c7-64bc-4732-87e2-a4276f6b2d5b","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01D8DNNK47kzaCFvJZxAAjY5","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_01TUTEXCeJwPs9iy8SsHVbed","name":"Bash","input":{"command":"grep -n \"v1.0.7\" \"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md\"","description":"Confirm v1.0.7 is gone from README"},"caller":{"type":"direct"}}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":2406,"cache_read_input_tokens":66168,"cache_creation":{"ephemeral_5m_input_tokens":2406,"ephemeral_1h_input_tokens":0},"output_tokens":1,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011CajwziTB6YJzPW3MTmrQ5","attributionAgent":"general-purpose","type":"assistant","uuid":"fad1ea8a-3ed5-4166-bde7-820f9e4f9341","timestamp":"2026-05-05T19:09:19.765Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"fad1ea8a-3ed5-4166-bde7-820f9e4f9341","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_01TUTEXCeJwPs9iy8SsHVbed","type":"tool_result","content":"13:The otel-collector's terminal exporter switches from `datadog` to `otlp` (gRPC pointed at `vector.vector.svc.cluster.local:4317`). The Datadog API key ownership moves from the otel-collector to the Vector module's ExternalSecret. The otel-collector module is pinned to `v1.1.0` which introduced the `downstream_endpoint` variable; `v1.0.7` and earlier are not compatible with this mode.","is_error":false}]},"uuid":"8d44d68a-3297-4f8f-b4de-c3fa4e674294","timestamp":"2026-05-05T19:09:20.372Z","sourceToolAssistantUUID":"fad1ea8a-3ed5-4166-bde7-820f9e4f9341","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"8d44d68a-3297-4f8f-b4de-c3fa4e674294","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01BknXSZ2br3jisUbMssYvQU","type":"message","role":"assistant","content":[{"type":"text","text":"The `v1.0.7` reference that remains is intentional — it's in the narrative prose explaining that v1.0.7 and earlier are not compatible with Vector mode (it's the \"before\" version called out for context, not a version reference to update). The Modules table now correctly shows `v1.1.0`."}],"stop_reason":null,"stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":410,"cache_read_input_tokens":68574,"cache_creation":{"ephemeral_5m_input_tokens":410,"ephemeral_1h_input_tokens":0},"output_tokens":1,"service_tier":"standard","inference_geo":"not_available"},"diagnostics":null},"requestId":"req_011Cajx14csdbFQNEuvgvo1R","attributionAgent":"general-purpose","type":"assistant","uuid":"cf61ba4f-1268-4325-aac5-3f7e1b461003","timestamp":"2026-05-05T19:09:23.890Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"cf61ba4f-1268-4325-aac5-3f7e1b461003","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01BknXSZ2br3jisUbMssYvQU","type":"message","role":"assistant","content":[{"type":"tool_use","id":"toolu_01VH5V11u7YiJ1xTn7E3n5CX","name":"Bash","input":{"command":"grep -n \"input_vector\" \"/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md\" | wc -l","description":"Count vector input anchors in inputs table"},"caller":{"type":"direct"}}],"stop_reason":"tool_use","stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":410,"cache_read_input_tokens":68574,"output_tokens":197,"server_tool_use":{"web_search_requests":0,"web_fetch_requests":0},"service_tier":"standard","cache_creation":{"ephemeral_1h_input_tokens":0,"ephemeral_5m_input_tokens":410},"inference_geo":"","iterations":[{"input_tokens":1,"output_tokens":197,"cache_read_input_tokens":68574,"cache_creation_input_tokens":410,"cache_creation":{"ephemeral_5m_input_tokens":410,"ephemeral_1h_input_tokens":0},"type":"message"}],"speed":"standard"},"diagnostics":null},"requestId":"req_011Cajx14csdbFQNEuvgvo1R","attributionAgent":"general-purpose","type":"assistant","uuid":"f07c3a93-483c-4ad8-aa58-0bff6dc2f50d","timestamp":"2026-05-05T19:09:24.448Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"f07c3a93-483c-4ad8-aa58-0bff6dc2f50d","isSidechain":true,"promptId":"c2f70b40-2e3f-4490-a13e-f038ff196213","agentId":"a995d77ad5955a4da","type":"user","message":{"role":"user","content":[{"tool_use_id":"toolu_01VH5V11u7YiJ1xTn7E3n5CX","type":"tool_result","content":" 13","is_error":false}]},"uuid":"984ba96f-a4a6-40dd-85dc-fb1b92b4c166","timestamp":"2026-05-05T19:09:25.067Z","sourceToolAssistantUUID":"f07c3a93-483c-4ad8-aa58-0bff6dc2f50d","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"} {"parentUuid":"984ba96f-a4a6-40dd-85dc-fb1b92b4c166","isSidechain":true,"agentId":"a995d77ad5955a4da","message":{"model":"claude-sonnet-4-6","id":"msg_01618b33zX1gqYjez1EbCkNn","type":"message","role":"assistant","content":[{"type":"text","text":"All 13 variables are present in the inputs table. Everything checks out.\n\n---\n\n**Status: DONE**\n\n**Summary of changes to `/Users/steve.briggs/projects/IAC/terraform/iac-library/aws/compute/eks-cluster-applications/README.md`:**\n\n- **Lines added:** 71 lines (file grew from 326 to 397 lines)\n- **Lines modified:** 1 (otel_collector module version bump)\n\n**Specific changes:**\n\n1. **New narrative section** (`## Vector (telemetry redaction aggregator)`) prepended before `## Requirements` (lines 1–55). Covers:\n - What Vector does and a link to the design spec at `../../../../docs/superpowers/specs/2026-05-05-vector-redaction-design.md`\n - Dual-mode data-flow diagrams (with-Vector vs. without-Vector)\n - Note about the otel-collector exporter swap and API key ownership move\n - How-to-enable HCL snippet with all 6 required variables\n - External-secrets dependency callout\n - Summary variable table (13 rows)\n\n2. **Module table** (Modules section): Added `module_vector` row (`v1.0.0`) in alphabetical position after `module_vault_sidecar_injector`.\n\n3. **Module table** (Modules section): Updated `module_otel_collector` version from `v1.0.7` to `v1.1.0`.\n\n4. **Inputs table**: Added 13 `vector_*` input rows in alphabetical order between `vault_sidecar_injector_version` and `vpc_id`.\n\n**Variables documented:** 13 (the task brief said 12, but `vector_external_secrets_cluster_store_name` is a 13th variable present in `vector.tf` — it's documented in both the narrative table and the Inputs table).\n\n**Existing otel-collector copy updated:** Yes — the Modules table version was bumped from `v1.0.7` to `v1.1.0`. The narrative section also explains the behavioral change (exporter swap from `datadog` to `otlp`, API key ownership moving to Vector). The `v1.0.7` mention that remains in the prose is intentional context (\"v1.0.7 and earlier are not compatible with this mode\").\n\n**Self-review findings:** Structure and formatting matches the existing terraform-docs style. No existing sections were disrupted. The narrative section follows the pattern of being placed before the auto-generated terraform-docs block (which is the only sensible place since the rest is pure table rows). The `vector_enabled_cluster_types` map default in the Inputs table uses `map(string)` to match `otel_collector_enabled_cluster_types` (the actual type in `vector.tf` is also `map(string)`). The `vector_email_redaction_replacement` default is quoted as `\"[REDACTED-EMAIL]\"` so the brackets don't break the Markdown table."}],"stop_reason":"end_turn","stop_sequence":null,"stop_details":null,"usage":{"input_tokens":1,"cache_creation_input_tokens":211,"cache_read_input_tokens":68984,"output_tokens":714,"server_tool_use":{"web_search_requests":0,"web_fetch_requests":0},"service_tier":"standard","cache_creation":{"ephemeral_1h_input_tokens":0,"ephemeral_5m_input_tokens":211},"inference_geo":"","iterations":[{"input_tokens":1,"output_tokens":714,"cache_read_input_tokens":68984,"cache_creation_input_tokens":211,"cache_creation":{"ephemeral_5m_input_tokens":211,"ephemeral_1h_input_tokens":0},"type":"message"}],"speed":"standard"},"diagnostics":null},"requestId":"req_011Cajx1QgNF7YgiQxkNHVMm","attributionAgent":"general-purpose","type":"assistant","uuid":"1d808f98-e699-475b-bb5f-b83403825826","timestamp":"2026-05-05T19:09:40.370Z","userType":"external","entrypoint":"cli","cwd":"/Users/steve.briggs/projects/IAC/terraform/internal-modules/kubernetes/monitoring/otel-collector","sessionId":"9c7db84f-6d53-4918-8d06-638ada15b7e9","version":"2.1.128","gitBranch":"HEAD"}