diff --git a/.env.example b/.env.example index 47f2c3b..0ee8079 100644 --- a/.env.example +++ b/.env.example @@ -71,6 +71,11 @@ SPLUNK_TOKEN= # FedRAMP stacks use https://admin.splunkcloudgc.com. # SPLUNK_ACS_BASE_URL= +# Hide the Cloud stack name at untrusted output boundaries (e.g. CI logs) in +# the target shown by prompts, JSON metadata, and error text. The audit log is +# unaffected -- it always records the real host. +# VCT_SPLUNK_REDACT_TARGET=1 + # --- Live test opt-ins ------------------------------------------------------- # Enables live read tests. Enterprise writes also require SPLUNK_WRITE_TEST=true. diff --git a/.github/scripts/run-cloud-suite.sh b/.github/scripts/run-cloud-suite.sh new file mode 100644 index 0000000..dabca12 --- /dev/null +++ b/.github/scripts/run-cloud-suite.sh @@ -0,0 +1,32 @@ +#!/usr/bin/env bash +# Run one Cloud pytest suite, tee its output, and publish a JUnit report. +# Shared by the read and write canary workflows so the pipefail/tee/exit +# dance lives in one place instead of being copy-pasted per step. +# +# Usage: run-cloud-suite.sh