audit-core/scripts/renew-runtime-lease.sh

24 lines
1 KiB
Bash
Raw Normal View History

#!/usr/bin/env bash
# Attended remint of the ESO orphan token, then force-sync the runtime lease.
# Never prints secret values. Run inside:
# warden access openbao-platform-admin-login --exec -- \
# env RAILIANCE01_KUBECONFIG="$HOME/.kube/config-railiance01" \
# "$PWD/scripts/renew-runtime-lease.sh"
set -euo pipefail
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
export RAILIANCE01_KUBECONFIG="${RAILIANCE01_KUBECONFIG:-$HOME/.kube/config-railiance01}"
export KUBECONFIG="$RAILIANCE01_KUBECONFIG"
export BAO_ADDR="${BAO_ADDR:-https://bao.coulomb.social}"
"$ROOT/scripts/openbao-eso-token-apply.sh"
# One read of database/creds/audit-core-runtime = one new lease. Annotate
# only the runtime ExternalSecret; migrate/senders follow on their own
# refresh once the store is Ready.
kubectl -n audit-core annotate externalsecret audit-core-database \
force-sync="$(date -u +%s)" --overwrite
echo "ESO token reminted and audit-core-database force-sync requested."
echo "Wait for ExternalSecret Ready=True; do not restart the receiver."