Decouple audit settings from tune
#476
Labels
feature
New feature or request
good first issue
Good for newcomers
help wanted
Extra attention is needed
Is your feature request related to a problem? Please describe.
Following up on a discussion it might make sense to separate
tune
options from audit tune options, as @cipherboy suggested:Describe the solution you'd like
Have way to tune audit settings independently of the
secrets tune
settings, allowing different roles to manage those.Describe alternatives you've considered
#474 was the starting point of the discussion which alternatively suggests removing some mountpoints from
untunableMounts
to allow tuning the audit settings in the first place. Doing #474 either by allowing to tune audit settings onsys
andidentity
or removing those mountpoints from untunables solves my issue but the suggested approach of splitting the paths feels better as it allows more granular control where it is (imho) warranted.Additional context
I personally feel like this change makes sense but at the same time it is a breaking change (it will break automation like Tofu) and I think it should be considered in the context of the bigger picture. Again, personally, I think this change is too substantial to be warranted doing alone and should rather be a part of a larger "package" that reworks auditing for example.
Imho #474 can be solved independently on this FR.
The text was updated successfully, but these errors were encountered: