diff --git a/argocd/platform-addons/secret-annotation-guard/README.md b/argocd/platform-addons/secret-annotation-guard/README.md index d4fe9c0..f2a31e6 100644 --- a/argocd/platform-addons/secret-annotation-guard/README.md +++ b/argocd/platform-addons/secret-annotation-guard/README.md @@ -35,10 +35,10 @@ That version copies ExternalSecret metadata when no target template exists; 31 current ExternalSecrets have no template. Removing annotations from targets alone cannot stop the controller adding them back. All 39 ExternalSecrets recovered after binding deletion; failed controllers were explicitly refreshed. -The policy remains installed but UNBOUND. `binding.pending.yaml` is deliberately -absent from kustomization. No ordinary sync of this revision enables enforcement. +The rollback revision `6016f72` left the policy UNBOUND and excluded the binding +from kustomization. That revision remains the immediate rollback target. -Before enabling: add explicit metadata templates in the 31 owning declarations, +Re-enablement prerequisite: add explicit metadata templates in the 31 owning declarations, preserving intended labels/annotations except last-applied; apply through owner paths; verify actual ESO refresh with annotation-free target Secrets. Retain existing data templates and remote references. Do not waive ESO from the policy @@ -54,3 +54,22 @@ Source for the diagnosed behavior: https://github.com/external-secrets/external-secrets/blob/v0.16.1/pkg/controllers/externalsecret/externalsecret_controller_template.go Detailed receipts: the-custodian/docs/evidence/2026-09-28-secret-annotation-*.json. + +## Corrected writer rollout + +On September 28 the founder authorized continuing the 31-declaration correction. +Metadata-only templates are committed and published across the 12 owning repos. +Server dry-run proved all 31 changes preserve the remaining ExternalSecret spec. +Direct owner resources used metadata-only SSA; Target Revenue used a selective +Argo sync of its ExternalSecret, with no migration/bootstrap hooks. All 39 +ExternalSecrets completed fresh successful refreshes before binding activation. + +`binding.yaml` is included for the reviewed re-enablement. After syncing, repeat +the native admission proof and require all 39 ExternalSecrets to complete fresh +refreshes with the binding present. Keep the safe annotation scan receipt and +report the absent-namespace orphan separately. No Secret values are read or +rotated by the metadata maintenance. ESO uses its normal credential refresh path. + +Detailed preflight, publication and before/after integration receipts live in +`the-custodian/docs/evidence/2026-09-28-eso-*.json`. The earlier rollout failure +and rescue remain recorded; remediation does not count as unchanged success. diff --git a/argocd/platform-addons/secret-annotation-guard/binding.pending.yaml b/argocd/platform-addons/secret-annotation-guard/binding.yaml similarity index 72% rename from argocd/platform-addons/secret-annotation-guard/binding.pending.yaml rename to argocd/platform-addons/secret-annotation-guard/binding.yaml index 2665523..4645cbf 100644 --- a/argocd/platform-addons/secret-annotation-guard/binding.pending.yaml +++ b/argocd/platform-addons/secret-annotation-guard/binding.yaml @@ -1,4 +1,4 @@ -# NOT included in kustomization: ESO v0.16.1 propagation must be fixed first. +# CUST-WP-0073: explicit ESO target metadata verified before re-enabling. apiVersion: admissionregistration.k8s.io/v1 kind: ValidatingAdmissionPolicyBinding metadata: diff --git a/argocd/platform-addons/secret-annotation-guard/kustomization.yaml b/argocd/platform-addons/secret-annotation-guard/kustomization.yaml index 8fca817..61acb08 100644 --- a/argocd/platform-addons/secret-annotation-guard/kustomization.yaml +++ b/argocd/platform-addons/secret-annotation-guard/kustomization.yaml @@ -2,3 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - policy.yaml + - binding.yaml