Close CCR drift and high-risk policy gaps
This commit is contained in:
parent
852a8ab661
commit
382f04412a
12 changed files with 577 additions and 68 deletions
|
|
@ -476,7 +476,8 @@ IONOS STARTTLS credentials and the shared user-engine ingest bearer for the
|
|||
| Policy file | `openbao/policies/workload-kv-read-email-connect-transactional.hcl` |
|
||||
| ESO policy | `external-secrets-email-connect` |
|
||||
| ESO policy file | `openbao/policies/external-secrets-email-connect.hcl` |
|
||||
| K8s auth role | `external-secrets-email-connect` (ESO delivery) |
|
||||
| Current ESO auth | policy-limited orphan token in Secret `external-secrets/openbao-email-connect-eso-token` |
|
||||
| K8s auth follow-up | role `external-secrets-email-connect` after the railiance01 auth mount is wired |
|
||||
| ClusterSecretStore | `openbao-email-connect` (namespace `email-connect` only) |
|
||||
| Primary consumer | ExternalSecret `email-connect/email-connect-runtime` → Secret `email-connect-runtime` |
|
||||
| Package manifests | `email-connect/deploy/k8s/railiance/` |
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue