RPF-WP-0046-T04: adopt eso-token-renewer Application (pinned b2ebe10); close RPF-WP-0045
- WP-0045-T06 done: both dead static-token Secrets deleted after a no-reference recheck. - Renewer Application moved from drafts to railiance01 applications; inert until the AppProject carries batch/CronJob and the root is synced by hand. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 150322@bnt-lap001 Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
This commit is contained in:
parent
fe1665d1d0
commit
7bf2df953d
4 changed files with 26 additions and 9 deletions
|
|
@ -2,7 +2,7 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
|
|
||||||
# RPF-WP-0046. Read only by the railiance01 Application in
|
# RPF-WP-0046. Read only by the railiance01 Application in
|
||||||
# argocd/railiance01/drafts/eso-token-renewer.application.yaml. No coulombcore
|
# argocd/railiance01/applications/eso-token-renewer.application.yaml. No coulombcore
|
||||||
# Application points here.
|
# Application points here.
|
||||||
|
|
||||||
namespace: external-secrets
|
namespace: external-secrets
|
||||||
|
|
|
||||||
|
|
@ -1,7 +1,6 @@
|
||||||
# DRAFT for railiance01 (RPF-WP-0046-T04). Not synced by any root: move to
|
# railiance01 child Application (RPF-WP-0046-T04, founder go-ahead 2026-09-23).
|
||||||
# ../applications/ only in T04, with the founder's go-ahead, after the
|
# Requires the platform-addons AppProject to carry batch/CronJob. No automated
|
||||||
# platform-addons AppProject carries batch/CronJob. No automated sync, no
|
# sync, no finalizer; targetRevision is the reviewed renewer commit.
|
||||||
# finalizer. Set targetRevision to the reviewed commit at adoption.
|
|
||||||
apiVersion: argoproj.io/v1alpha1
|
apiVersion: argoproj.io/v1alpha1
|
||||||
kind: Application
|
kind: Application
|
||||||
metadata:
|
metadata:
|
||||||
|
|
@ -16,7 +15,7 @@ spec:
|
||||||
project: railiance-platform-addons
|
project: railiance-platform-addons
|
||||||
source:
|
source:
|
||||||
repoURL: https://forgejo.coulomb.social/coulomb/railiance-platform.git
|
repoURL: https://forgejo.coulomb.social/coulomb/railiance-platform.git
|
||||||
targetRevision: PIN-AT-ADOPTION
|
targetRevision: b2ebe108495c4d06ebb6ca33893ea4a2a23c9725
|
||||||
path: argocd/platform-addons/eso-token-renewer
|
path: argocd/platform-addons/eso-token-renewer
|
||||||
destination:
|
destination:
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
|
|
@ -4,12 +4,12 @@ type: workplan
|
||||||
title: "Move openbao-activity-core and openbao-email-connect off expired static tokens to Kubernetes auth"
|
title: "Move openbao-activity-core and openbao-email-connect off expired static tokens to Kubernetes auth"
|
||||||
domain: financials
|
domain: financials
|
||||||
repo: railiance-platform
|
repo: railiance-platform
|
||||||
status: active
|
status: finished
|
||||||
flavor: implementation
|
flavor: implementation
|
||||||
owner: railiance-platform
|
owner: railiance-platform
|
||||||
topic_slug: railiance
|
topic_slug: railiance
|
||||||
created: "2026-09-21"
|
created: "2026-09-21"
|
||||||
updated: "2026-09-22"
|
updated: "2026-09-23"
|
||||||
related: [RPF-WP-0037]
|
related: [RPF-WP-0037]
|
||||||
state_hub_workstream_id: "0edc6426-9cc8-5bbe-88ea-c27d9862d96e"
|
state_hub_workstream_id: "0edc6426-9cc8-5bbe-88ea-c27d9862d96e"
|
||||||
---
|
---
|
||||||
|
|
@ -224,7 +224,7 @@ RPF-WP-0037 does.
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: RPF-WP-0045-T06
|
id: RPF-WP-0045-T06
|
||||||
status: wait
|
status: done
|
||||||
priority: medium
|
priority: medium
|
||||||
state_hub_task_id: "f56d7096-e005-5dd5-afa0-b1affe247fa7"
|
state_hub_task_id: "f56d7096-e005-5dd5-afa0-b1affe247fa7"
|
||||||
```
|
```
|
||||||
|
|
@ -295,3 +295,12 @@ and `email-connect/deploy/k8s/railiance/openbao-eso-token-apply.sh`, and update
|
||||||
failing (four in core-hub, two in tenant-engine). This is the failure mode
|
failing (four in core-hub, two in tenant-engine). This is the failure mode
|
||||||
named in the Risks section above. It needs the same Kubernetes-auth
|
named in the Risks section above. It needs the same Kubernetes-auth
|
||||||
migration, with an attended admin login.
|
migration, with an attended admin login.
|
||||||
|
|
||||||
|
## Closure — 2026-09-23
|
||||||
|
|
||||||
|
- **T06 done.** Founder go-ahead 2026-09-23. A recheck found no store
|
||||||
|
referencing either Secret, so both were deleted:
|
||||||
|
`external-secrets/openbao-activity-core-eso-token` and
|
||||||
|
`openbao-email-connect-eso-token`. The bootstrap targets were retired by
|
||||||
|
their owners: activity-core `b690ce0`, confirmed in hub message `65b1387a`.
|
||||||
|
email-connect was notified.
|
||||||
|
|
|
||||||
|
|
@ -124,6 +124,15 @@ state_hub_task_id: "28726b1b-3777-5945-859b-9e563b12fee6"
|
||||||
`kubectl -n external-secrets create job --from=cronjob/eso-token-renewer eso-token-renewer-first`.
|
`kubectl -n external-secrets create job --from=cronjob/eso-token-renewer eso-token-renewer-first`.
|
||||||
Every lane must print `ok: true` with a TTL of 604800.
|
Every lane must print `ok: true` with a TTL of 604800.
|
||||||
|
|
||||||
|
T04 progress, 2026-09-23 (founder go-ahead):
|
||||||
|
|
||||||
|
- A `kubectl diff` of the AppProject showed only `+ batch/CronJob`. The
|
||||||
|
session's permission guard blocked the apply ("Shared Cluster Mutation"), so
|
||||||
|
the founder runs step 1.
|
||||||
|
- Step 2 is done in git. The Application was moved to
|
||||||
|
`argocd/railiance01/applications/` and pinned to `b2ebe10`. The root has no
|
||||||
|
automated sync, so nothing changes until the manual root sync.
|
||||||
|
|
||||||
## T05 Move consumers off leases from the old tokens before 2026-10-25
|
## T05 Move consumers off leases from the old tokens before 2026-10-25
|
||||||
|
|
||||||
```task
|
```task
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue