# Production pin for the tenant-engine policy service. Independently rollable. # Warn is safe whether or not the live tenant-engine client already sends a # token. Do not flip this pin to enforce until its warn logs are clean. name: flex-auth-tenant-engine image: repository: forgejo.coulomb.social/coulomb/flex-auth digest: sha256:138aa3471c46bca6e814691fa1e6520aedda3dffd743e6b09141ab433afdb64b args: - serve - --addr - 0.0.0.0:8080 - --registry - /opt/flex-auth/examples/tenant-engine/registry_snapshot.json - --policy - /opt/flex-auth/examples/tenant-engine/policy_package.md callerAuth: mode: warn kubernetesURL: https://10.43.0.1 binding: tenant-engine=system:serviceaccount:tenant-engine:tenant-engine consumer: isolated: false namespace: tenant-engine podName: tenant-engine