# Non-secret sender scope (AUDIT-WP-0006-T05). Tokens stay in Secret # audit-core-senders. This ConfigMap is the authority for tenants/sources # so an ExternalSecret refresh cannot revert user-engine to a single tenant. # Keep in lockstep with deploy/senders-scope.json. --- apiVersion: v1 kind: ConfigMap metadata: name: audit-core-senders-scope namespace: audit-core labels: app.kubernetes.io/name: audit-core data: senders-scope.json: | [ { "name": "user-engine", "sources": ["user-engine"], "tenants": ["*"], "may_write": true, "may_read": false } ]