# Credential delivery for audit-core (AUDIT-WP-0005-T02). # # Two sources, because they are two kinds of secret: # - database leases: VaultDynamicSecret -> ExternalSecret (this file) # - sender registry: ClusterSecretStore openbao-audit-core -> ExternalSecret # # audit-core never holds a credential in its own configuration; it reads # whatever is currently mounted. Apply order: namespace, ESO token, # ClusterSecretStore, VaultDynamicSecret, this, migrate Job, Deployment. --- apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: audit-core-database namespace: audit-core spec: # Shorter than the platform default of 1h: these are dynamic leases, and the # refresh interval bounds how long a revoked lease can remain mounted. refreshInterval: 15m target: name: audit-core-database creationPolicy: Owner deletionPolicy: Retain template: engineVersion: v2 # One value per file. The pod mounts this Secret as a directory and # audit-core re-reads it on every connection attempt, so a rotated lease # takes effect without a restart and without a delivery gap. data: username: "{{ .username }}" password: "{{ .password }}" host: platform-pg-rw.databases.svc.cluster.local port: "5432" dbname: audit_core dataFrom: - sourceRef: generatorRef: apiVersion: generators.external-secrets.io/v1alpha1 kind: VaultDynamicSecret name: audit-core-runtime --- apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: audit-core-database-migrate namespace: audit-core spec: refreshInterval: 15m target: name: audit-core-database-migrate creationPolicy: Owner deletionPolicy: Retain template: engineVersion: v2 data: username: "{{ .username }}" password: "{{ .password }}" host: platform-pg-rw.databases.svc.cluster.local port: "5432" dbname: audit_core dataFrom: - sourceRef: generatorRef: apiVersion: generators.external-secrets.io/v1alpha1 kind: VaultDynamicSecret name: audit-core-migration --- apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: audit-core-senders namespace: audit-core spec: refreshInterval: 1h secretStoreRef: kind: ClusterSecretStore name: openbao-audit-core target: name: audit-core-senders creationPolicy: Owner deletionPolicy: Retain data: # The sender registry: which credential may write for which tenant and # source, and each sender's secret_policy. Held in OpenBao rather than the # manifest because it contains bearer tokens. # # Rotation is overlap-first: add the replacement to a sender's `tokens` # list, move the sender, then drop the predecessor. Both are valid in # between, so there is no delivery gap. - secretKey: senders.json remoteRef: # CSS already mounts KV path `platform`; do not repeat the prefix. key: workloads/audit-core/senders property: senders.json