flex-auth/deploy/caller-auth-rbac.yaml
tegwick 1e1e077b27 Implement inbound caller authentication (ADR 0004); close T03 and T05
TokenReview-based caller identity with audience-scoped tokens and exact
resource.system to ServiceAccount bindings, per ops-warden's recommendation.
Deletes the unwired tenant-engine live-roles adapter (T03) and adds
make verify-posture (T05). Source implements A2; running digest is still A0
until promotion, so tenancy.current.A stays 0.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 15:22:52 +02:00

51 lines
1.1 KiB
YAML

apiVersion: v1
kind: ServiceAccount
metadata:
name: flex-auth-tenant-engine
namespace: flex-auth
automountServiceAccountToken: false
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: flex-auth-user-engine
namespace: flex-auth
automountServiceAccountToken: false
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: flex-auth-tokenreviewer
rules:
- apiGroups:
- authentication.k8s.io
resources:
- tokenreviews
verbs:
- create
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: flex-auth-tenant-engine-tokenreviewer
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: flex-auth-tokenreviewer
subjects:
- kind: ServiceAccount
name: flex-auth-tenant-engine
namespace: flex-auth
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: flex-auth-user-engine-tokenreviewer
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: flex-auth-tokenreviewer
subjects:
- kind: ServiceAccount
name: flex-auth-user-engine
namespace: flex-auth