You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the Vault CLI module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
12 / 17
18 / 20
1 / 20
8 / 10
58 / 100
Drilldown
Presentation & Onboarding — 12 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
12
README documents distinct modes with working examples: basic CLI-only install, token auth, pinned version, custom install_dir, Enterprise namespace, and Enterprise binary — each with sensible defaults shown inline.
Visual preview
5
0
No image, GIF, or video anywhere in the README.
Credential Hygiene — 18 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
vault_token is declared sensitive = true in main.tf, and every README example references var.vault_token rather than inlining a literal token value.
Non-hardcoded auth path
4
2
"Related Modules" section points to vault-github and vault-jwt for OIDC/JWT-based auth as alternatives to raw tokens, but this is only a cross-reference, not a path implemented or walked through in this module's own examples.
Restricted-Environment Readiness — 1 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
0
No variable overrides the download URL. run.sh hardcodes api.releases.hashicorp.com and releases.hashicorp.com; none of the module's inputs (install_dir, vault_cli_version, enterprise, etc.) replace these.
Bring-your-own binary
10
0
No documented flag to skip install entirely. The script only skips reinstall automatically if an existing vault binary happens to match the resolved target version — this is undocumented incidental behavior, not a declared BYOB mode.
Egress transparency
3
0
No dedicated network/air-gapped section in the README; the api.releases.hashicorp.com and releases.hashicorp.com endpoints are visible only in run.sh, not documented.
Runs without sudo
2
1
run.sh first tries a non-root mv into INSTALL_DIR or /usr/local/bin, only invoking sudo as a fallback, and falls back further to ~/.local/bin if sudo also fails — a working non-root path exists but sudo is used for the default/optional path, earning half.
Engineering Quality — 8 / 10
Criterion
Max
Score
Notes
Input quality
6
6
All variables have clear descriptions and sensible defaults (install_dir = /usr/local/bin, vault_cli_version = "latest", enterprise = false); vault_cli_version has a regex validation block.
Test coverage
4
2
main.tftest.hcl thoroughly exercises Terraform wiring (env vars, outputs, version validation) across many scenarios, but there is no TypeScript/e2e test exercising the actual run.sh install logic.
Overall — 58 / 100
Raw 39 / 67 → round(39 / 67 × 100) = 58
Scored against SCORECARD.md on 2026-10-05 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the Vault CLI module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 12 / 17
install_dir, Enterprise namespace, and Enterprise binary — each with sensible defaults shown inline.Credential Hygiene — 18 / 20
vault_tokenis declaredsensitive = trueinmain.tf, and every README example referencesvar.vault_tokenrather than inlining a literal token value.vault-githubandvault-jwtfor OIDC/JWT-based auth as alternatives to raw tokens, but this is only a cross-reference, not a path implemented or walked through in this module's own examples.Restricted-Environment Readiness — 1 / 20
run.shhardcodesapi.releases.hashicorp.comandreleases.hashicorp.com; none of the module's inputs (install_dir,vault_cli_version,enterprise, etc.) replace these.vaultbinary happens to match the resolved target version — this is undocumented incidental behavior, not a declared BYOB mode.api.releases.hashicorp.comandreleases.hashicorp.comendpoints are visible only inrun.sh, not documented.run.shfirst tries a non-rootmvintoINSTALL_DIRor/usr/local/bin, only invokingsudoas a fallback, and falls back further to~/.local/binif sudo also fails — a working non-root path exists but sudo is used for the default/optional path, earning half.Engineering Quality — 8 / 10
install_dir = /usr/local/bin,vault_cli_version = "latest",enterprise = false);vault_cli_versionhas a regexvalidationblock.main.tftest.hclthoroughly exercises Terraform wiring (env vars, outputs, version validation) across many scenarios, but there is no TypeScript/e2e test exercising the actualrun.shinstall logic.Overall — 58 / 100
Raw 39 / 67 → round(39 / 67 × 100) = 58
Scored against SCORECARD.md on 2026-10-05 with
solstice-1.All reactions