Add attended runtime-lease remint helper for the expired ESO token
The 768h orphan token in external-secrets/openbao-audit-core-eso-token expired at 2026-09-14T10:23Z and ClusterSecretStore lookup-self is 403, so ESO cannot mint database/creds/audit-core-runtime. Recreate the Kubernetes Secret without last-applied-configuration so the token is not stored in annotation metadata. Assistant: grok Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
This commit is contained in:
parent
cf8c740b1b
commit
ca6a608b16
2 changed files with 28 additions and 3 deletions
|
|
@ -93,10 +93,12 @@ if kubectl get ns core-hub-staging >/dev/null 2>&1; then
|
|||
echo "ERROR: kubeconfig looks like coulombcore (namespace core-hub-staging present)." >&2
|
||||
exit 1
|
||||
fi
|
||||
# Recreate rather than kubectl-apply: apply writes the token into
|
||||
# last-applied-configuration, which is readable as Secret metadata.
|
||||
kubectl -n "$SECRET_NS" delete secret "$SECRET_NAME" --ignore-not-found
|
||||
kubectl -n "$SECRET_NS" create secret generic "$SECRET_NAME" \
|
||||
--from-literal=token="$child_token" \
|
||||
--dry-run=client -o yaml | kubectl apply -f -
|
||||
--from-literal=token="$child_token"
|
||||
|
||||
unset child_token BAO_TOKEN
|
||||
echo "Secret $SECRET_NS/$SECRET_NAME applied on railiance01."
|
||||
echo "Next: apply ClusterSecretStore openbao-audit-core, then deploy/."
|
||||
echo "Next: force-sync ExternalSecret audit-core-database; do not bounce the pod."
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue