## Summary - Fix Ansible secret example: replaced incorrect `op item get --fields` with `op read` to match project convention - Add new "Tailscale Operator Privileges" section documenting the operator's namespaced RBAC and OAuth client permissions - Stamp `last-reviewed: 2026-02-11` ## Review Notes First review of this doc (previously never reviewed). Verified: - All wiki-links resolve - ACL structure matches actual `pulumi/tailscale/policy.hujson` - TruffleHog pre-commit config exists as documented - Ansible `op read` pattern matches actual usage in playbooks/roles Reviewed-on: https://forge.ops.eblu.me/eblume/blumeops/pulls/153 |
||
|---|---|---|
| .. | ||
| architecture.md | ||
| explanation.md | ||
| security-model.md | ||
| why-gitops.md | ||