fix(security): hold annotation enforcement until ESO metadata is explicit
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e7fb-275d-7db0-b1df-39ed943427da
This commit is contained in:
parent
54885ac158
commit
6016f72a8d
5 changed files with 111 additions and 10 deletions
|
|
@ -21,3 +21,36 @@ Rollback is a manual Argo sync of a reviewed revision without the binding
|
|||
(with explicit resource-scoped pruning), or attended break-glass deletion of
|
||||
the binding followed by Git reconciliation. Removing the binding reopens this
|
||||
leak path. The policy does not rotate credentials or isolate agent accounts.
|
||||
|
||||
## September 28 rollout and rollback
|
||||
|
||||
Policy source `800cbfa` and Application declaration `54885ac` were deployed
|
||||
through manual, resource-scoped Argo sync. Native type checking passed. Nine
|
||||
synthetic checks passed: clean creation/update/server apply, rejection of
|
||||
annotated create/update including empty values, client-side apply rejection,
|
||||
and fixture cleanup.
|
||||
|
||||
Enforcement was rolled back when ESO v0.16.1 targets stopped refreshing.
|
||||
That version copies ExternalSecret metadata when no target template exists;
|
||||
31 current ExternalSecrets have no template. Removing annotations from targets
|
||||
alone cannot stop the controller adding them back. All 39 ExternalSecrets
|
||||
recovered after binding deletion; failed controllers were explicitly refreshed.
|
||||
The policy remains installed but UNBOUND. `binding.pending.yaml` is deliberately
|
||||
absent from kustomization. No ordinary sync of this revision enables enforcement.
|
||||
|
||||
Before enabling: add explicit metadata templates in the 31 owning declarations,
|
||||
preserving intended labels/annotations except last-applied; apply through owner
|
||||
paths; verify actual ESO refresh with annotation-free target Secrets. Retain
|
||||
existing data templates and remote references. Do not waive ESO from the policy
|
||||
or upgrade the controller as a shortcut. Rerun cleanup, native admission tests
|
||||
and an ESO refresh integration test, then include the binding and update the pin.
|
||||
|
||||
The absent `platform-pg-drill` namespace still has an orphan Secret `drill-minio`,
|
||||
a Deployment referencing it, a PVC and Service. Metadata patch fails because the
|
||||
namespace is absent. No orphan object was deleted or namespace recreated. Its
|
||||
disposition stays in CUST-WP-0073-T03; do not report cluster-wide cleanup complete.
|
||||
|
||||
Source for the diagnosed behavior:
|
||||
https://github.com/external-secrets/external-secrets/blob/v0.16.1/pkg/controllers/externalsecret/externalsecret_controller_template.go
|
||||
|
||||
Detailed receipts: the-custodian/docs/evidence/2026-09-28-secret-annotation-*.json.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue