Close CCR drift and high-risk policy gaps
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

This commit is contained in:
codex 2026-08-21 01:29:28 +02:00
parent 852a8ab661
commit 382f04412a
12 changed files with 577 additions and 68 deletions

View file

@ -476,7 +476,8 @@ IONOS STARTTLS credentials and the shared user-engine ingest bearer for the
| Policy file | `openbao/policies/workload-kv-read-email-connect-transactional.hcl` |
| ESO policy | `external-secrets-email-connect` |
| ESO policy file | `openbao/policies/external-secrets-email-connect.hcl` |
| K8s auth role | `external-secrets-email-connect` (ESO delivery) |
| Current ESO auth | policy-limited orphan token in Secret `external-secrets/openbao-email-connect-eso-token` |
| K8s auth follow-up | role `external-secrets-email-connect` after the railiance01 auth mount is wired |
| ClusterSecretStore | `openbao-email-connect` (namespace `email-connect` only) |
| Primary consumer | ExternalSecret `email-connect/email-connect-runtime` → Secret `email-connect-runtime` |
| Package manifests | `email-connect/deploy/k8s/railiance/` |