#!/usr/bin/env bash # Attended remint of the ESO orphan token, then force-sync the runtime lease. # Never prints secret values. Run inside: # warden access openbao-platform-admin-login --exec -- \ # env RAILIANCE01_KUBECONFIG="$HOME/.kube/config-railiance01" \ # "$PWD/scripts/renew-runtime-lease.sh" set -euo pipefail ROOT="$(cd "$(dirname "$0")/.." && pwd)" export RAILIANCE01_KUBECONFIG="${RAILIANCE01_KUBECONFIG:-$HOME/.kube/config-railiance01}" export KUBECONFIG="$RAILIANCE01_KUBECONFIG" export BAO_ADDR="${BAO_ADDR:-https://bao.coulomb.social}" "$ROOT/scripts/openbao-eso-token-apply.sh" # One read of database/creds/audit-core-runtime = one new lease. Annotate # only the runtime ExternalSecret; migrate/senders follow on their own # refresh once the store is Ready. kubectl -n audit-core annotate externalsecret audit-core-database \ force-sync="$(date -u +%s)" --overwrite echo "ESO token reminted and audit-core-database force-sync requested." echo "Wait for ExternalSecret Ready=True; do not restart the receiver."