RepoJournal
HashiCorp

@hashicorp

Terraform, Vault, Consul — infra-as-code for ops teams

Pick a date

The Wire · Showcase

VAULT OPERATOR ADOPTS TERRATEST 1.0, CONSUL DUMPS NODE20 RUNTIMES

By RepoJournal · Filed · About HashiCorp

Vault Secrets Operator moved to Terratest's first stable release while Consul and TFE Helm tightened CI security posture across the org.

Vault Secrets Operator cut over to Terratest 1.0.0 [1], the testing library's first stable release after years of development. Simultaneously, the same repo pulled four backward-compatible updates [2] including new versions of go-openapi/strfmt, gomega, and google.golang.org/api. Over in Consul, the team eliminated tech debt by migrating all GitHub Actions workflows from deprecated Node 20 to Node 24 [3] [4], closing out a compliance window before EOL. TFE Helm followed suit with least-privilege permissions enforcement [5], adding explicit read-only blocks to their CI workflow after the org moved to secure-by-default. Meanwhile, Consul-K8s shipped a critical ACL policy fix [6] that restores mesh gateway cross-partition permissions needed for Sameness Group failover in partitioned deployments. The fix expands test coverage across peering and namespace combinations to catch regressions.

Action items

References

  1. [1] Bump github.com/gruntwork-io/terratest from 0.56.0 to 1.0.0 in the gomod-breaking group across 1 directory ↗ hashicorp/vault-secrets-operator
  2. [2] Bump the gomod-backward-compatible group with 4 updates ↗ hashicorp/vault-secrets-operator
  3. [3] update all actions which were using deprecated node20 to node24 ↗ hashicorp/consul
  4. [4] update all actions which were using deprecated node20 to node24 (#23687) hashicorp/consul
  5. [5] TF-38688 add required gha permission to workflows ↗ hashicorp/terraform-enterprise-helm
  6. [6] fix: update mesh gateway rules for peering and partition handling ↗ hashicorp/consul-k8s

FAQ

What changed in HashiCorp on June 30, 2026?
Vault Secrets Operator moved to Terratest's first stable release while Consul and TFE Helm tightened CI security posture across the org.
What should HashiCorp teams do about it?
Verify Vault Secrets Operator integration tests pass with Terratest 1.0.0 before next deployment • Audit your fork's CI workflows for deprecated Node 20 runtimes and upgrade to Node 24 • Review mesh gateway ACL policies if running Consul-K8s with Admin Partitions and Sameness Groups
Which HashiCorp repositories shipped on June 30, 2026?
hashicorp/vault-secrets-operator, hashicorp/consul, hashicorp/terraform-enterprise-helm, hashicorp/consul-k8s

Related across the cluster

For your repos

The showcase is a teaser.
Your wire is the product.

Same engine. Different stack. Below: what changes when the wire is yours.

Showcase wire

  • 14 famous open source orgs
  • One wire per day
  • Public, generic
  • Read on the web, when you remember

Your wire

  • Up to 1,500 of your repos - orgs, deps, vendors
  • Morning and evening briefs
  • Action items routed to your team
  • Slack delivery, email, breaking-news CVE alerts

Want a hands-on demo first? Ask a current user for an invite link.