RPF-WP-0045: plan Kubernetes-auth migration for openbao-activity-core and openbao-email-connect
Declares target store specs, two exact-path policies and two ESO ServiceAccounts. Nothing applied; live steps wait on the founder. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 63291@bnt-lap001 Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
This commit is contained in:
parent
2d79c2e4e5
commit
6e399bbe64
6 changed files with 347 additions and 25 deletions
16
openbao/eso-auth-recovery/rpf-wp-0045-serviceaccounts.yaml
Normal file
16
openbao/eso-auth-recovery/rpf-wp-0045-serviceaccounts.yaml
Normal file
|
|
@ -0,0 +1,16 @@
|
|||
# RPF-WP-0045: dedicated ESO identities for the two stores still on static
|
||||
# tokens. Not applied by the RPF-WP-0037 helper (it reads serviceaccounts.yaml).
|
||||
# Apply only in RPF-WP-0045-T03, after the founder's go-ahead.
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: activity-core-eso
|
||||
namespace: activity-core
|
||||
automountServiceAccountToken: false
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: email-connect-eso
|
||||
namespace: email-connect
|
||||
automountServiceAccountToken: false
|
||||
28
openbao/policies/workload-kv-read-activity-core-eso.hcl
Normal file
28
openbao/policies/workload-kv-read-activity-core-eso.hcl
Normal file
|
|
@ -0,0 +1,28 @@
|
|||
# RPF-WP-0045: ESO delivery for ClusterSecretStore openbao-activity-core via
|
||||
# Kubernetes auth role activity-core-eso (SA activity-core/activity-core-eso).
|
||||
# Exactly the four KV paths the four activity-core ExternalSecrets read; data
|
||||
# read only, no metadata/list/write. ESO also needs lookup-self and revoke-self.
|
||||
|
||||
path "platform/data/workloads/activity-core/llm-connect/llm-connect-provider-secrets" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
|
||||
path "platform/data/workloads/issue-core/issue-core/issue-core-runtime" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
|
||||
path "platform/data/workloads/forgejo/forgejo-admin" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
|
||||
path "platform/data/workloads/railiance/backup/offsite-lane" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
|
||||
path "auth/token/lookup-self" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
|
||||
path "auth/token/revoke-self" {
|
||||
capabilities = ["update"]
|
||||
}
|
||||
|
|
@ -0,0 +1,15 @@
|
|||
# RPF-WP-0045: ESO delivery for ClusterSecretStore openbao-email-connect via
|
||||
# Kubernetes auth role email-connect-transactional-eso
|
||||
# (SA email-connect/email-connect-eso). One exact KV data read.
|
||||
|
||||
path "platform/data/workloads/email-connect/transactional" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
|
||||
path "auth/token/lookup-self" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
|
||||
path "auth/token/revoke-self" {
|
||||
capabilities = ["update"]
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue