audit-core/deploy/senders-scope.yaml
tegwick ded432a63f
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Implement AUDIT-WP-0006 honest operational custody.
Postgres now reports custody_class=operational with a cited 30-day
recoverable window. Join ITC-CAP operations.audit at D4, publish the
interface card, and overlay user-engine tenants [*] from Git so an
ExternalSecret refresh cannot shrink it.
2026-08-16 00:24:33 +02:00

23 lines
626 B
YAML

# Non-secret sender scope (AUDIT-WP-0006-T05). Tokens stay in Secret
# audit-core-senders. This ConfigMap is the authority for tenants/sources
# so an ExternalSecret refresh cannot revert user-engine to a single tenant.
# Keep in lockstep with deploy/senders-scope.json.
---
apiVersion: v1
kind: ConfigMap
metadata:
name: audit-core-senders-scope
namespace: audit-core
labels:
app.kubernetes.io/name: audit-core
data:
senders-scope.json: |
[
{
"name": "user-engine",
"sources": ["user-engine"],
"tenants": ["*"],
"may_write": true,
"may_read": false
}
]