audit-core/deploy
tegwick c404c910cd Read mounted DB credentials from a Kubernetes snapshot
Secret volume rotation swaps ..data. Sequential reads of username then
password can tear across two leases. Resolve the snapshot once.

Also document why ESO AppRole login cannot parent database/creds leases:
the token discard DROP ROLEs the role ESO just stored.
2026-08-13 12:25:32 +02:00
..
audit-core.yaml Stand up railiance01 receiver without founder bao kv put 2026-08-13 10:27:13 +02:00
clustersecretstore.yaml Read mounted DB credentials from a Kubernetes snapshot 2026-08-13 12:25:32 +02:00
externalsecret-senders.yaml Stand up railiance01 receiver without founder bao kv put 2026-08-13 10:27:13 +02:00
externalsecrets.yaml Stand up railiance01 receiver without founder bao kv put 2026-08-13 10:27:13 +02:00
migrate-job.yaml Stand up railiance01 receiver without founder bao kv put 2026-08-13 10:27:13 +02:00
networkpolicies.yaml Add deployment manifests, custody-class guard and request counters 2026-08-10 17:42:43 +02:00
README.md Pin audit-core image digest 41493cd5 for railiance01 2026-08-13 00:59:51 +02:00

railiance01 package

Target: railiance01 only. The workstation kubeconfig that talks to that API is the k3s-api-railiance01 tunnel (local port 16444). ~/.kube/config-hosteurope currently points at 16443 (coulombcore); rewrite the server port or export a copy before applying.

Apply order is documented in docs/operator-runbook.md. Do not apply the Deployment until:

  1. The image digest is pinned (currently sha256:41493cd5… from commit 3a7d63e).
  2. Secrets audit-core-database, audit-core-database-migrate, and audit-core-senders exist.
  3. Job audit-core-migrate has completed.
make image-build
make deploy-dry-run