From 943b246bde5e8836ec657b72de67673f160c07f5 Mon Sep 17 00:00:00 2001 From: chen21019 Date: Wed, 9 Sep 2026 19:06:00 +0800 Subject: [PATCH] docs: align current release coordinates --- README.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/README.md b/README.md index 2c2f3aa..db1f8e2 100644 --- a/README.md +++ b/README.md @@ -6,6 +6,10 @@ PastureStack is an independent community effort to preserve, audit, and moderniz `vault-secrets-bridge` is the PastureStack host-authenticated broker for short-lived HashiCorp Vault leases. It accepts only fresh requests signed by an active host identity, enforces an explicit policy allowlist, asks Vault for a response-wrapped child token, encrypts that wrapping token to the requesting host, and tracks only the revocable accessor under a hashed host-and-volume key. +The current public release and Catalog image are `v0.1.1`. This repository does +not publish a mutable `latest` tag; future releases must use an unused pure +numeric version. + The companion `secrets-flexvolume-plugin` runs as a separate host-local Docker volume driver with `--provider vault`. It verifies and decrypts the returned envelope, writes the wrapping token to a read-only file in an isolated `tmpfs`, and asks this bridge to revoke the lease after the final workload unmounts the volume. ## Runtime entry point