Commit Graph
2 Commits
Author SHA1 Message Date
slawekandClaude Sonnet 5 91f1abef8a Add Vault auto-unseal service and 1Password bootstrap script
Add vault-tpm2-unseal.sh/.service to unseal Vault once after boot using
the TPM-sealed key, and tpm-bootstrap-1password.sh to (re)seal that key
from a 1Password secret reference. Document PCR policy selection, the
Vault service, and the host-specific tpm2.env (gitignored, example in
README) in README.md.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-29 14:19:35 +02:00
slawek c5ed8b77ac Generated seal unseal store and read scripts for TPM. 2026-08-29 12:24:22 +02:00