fix(security): rebind annotation guard after ESO metadata remediation
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e7fb-275d-7db0-b1df-39ed943427da
This commit is contained in:
parent
d2631f6112
commit
7daf7e9067
3 changed files with 24 additions and 4 deletions
|
|
@ -35,10 +35,10 @@ That version copies ExternalSecret metadata when no target template exists;
|
||||||
31 current ExternalSecrets have no template. Removing annotations from targets
|
31 current ExternalSecrets have no template. Removing annotations from targets
|
||||||
alone cannot stop the controller adding them back. All 39 ExternalSecrets
|
alone cannot stop the controller adding them back. All 39 ExternalSecrets
|
||||||
recovered after binding deletion; failed controllers were explicitly refreshed.
|
recovered after binding deletion; failed controllers were explicitly refreshed.
|
||||||
The policy remains installed but UNBOUND. `binding.pending.yaml` is deliberately
|
The rollback revision `6016f72` left the policy UNBOUND and excluded the binding
|
||||||
absent from kustomization. No ordinary sync of this revision enables enforcement.
|
from kustomization. That revision remains the immediate rollback target.
|
||||||
|
|
||||||
Before enabling: add explicit metadata templates in the 31 owning declarations,
|
Re-enablement prerequisite: add explicit metadata templates in the 31 owning declarations,
|
||||||
preserving intended labels/annotations except last-applied; apply through owner
|
preserving intended labels/annotations except last-applied; apply through owner
|
||||||
paths; verify actual ESO refresh with annotation-free target Secrets. Retain
|
paths; verify actual ESO refresh with annotation-free target Secrets. Retain
|
||||||
existing data templates and remote references. Do not waive ESO from the policy
|
existing data templates and remote references. Do not waive ESO from the policy
|
||||||
|
|
@ -54,3 +54,22 @@ Source for the diagnosed behavior:
|
||||||
https://github.com/external-secrets/external-secrets/blob/v0.16.1/pkg/controllers/externalsecret/externalsecret_controller_template.go
|
https://github.com/external-secrets/external-secrets/blob/v0.16.1/pkg/controllers/externalsecret/externalsecret_controller_template.go
|
||||||
|
|
||||||
Detailed receipts: the-custodian/docs/evidence/2026-09-28-secret-annotation-*.json.
|
Detailed receipts: the-custodian/docs/evidence/2026-09-28-secret-annotation-*.json.
|
||||||
|
|
||||||
|
## Corrected writer rollout
|
||||||
|
|
||||||
|
On September 28 the founder authorized continuing the 31-declaration correction.
|
||||||
|
Metadata-only templates are committed and published across the 12 owning repos.
|
||||||
|
Server dry-run proved all 31 changes preserve the remaining ExternalSecret spec.
|
||||||
|
Direct owner resources used metadata-only SSA; Target Revenue used a selective
|
||||||
|
Argo sync of its ExternalSecret, with no migration/bootstrap hooks. All 39
|
||||||
|
ExternalSecrets completed fresh successful refreshes before binding activation.
|
||||||
|
|
||||||
|
`binding.yaml` is included for the reviewed re-enablement. After syncing, repeat
|
||||||
|
the native admission proof and require all 39 ExternalSecrets to complete fresh
|
||||||
|
refreshes with the binding present. Keep the safe annotation scan receipt and
|
||||||
|
report the absent-namespace orphan separately. No Secret values are read or
|
||||||
|
rotated by the metadata maintenance. ESO uses its normal credential refresh path.
|
||||||
|
|
||||||
|
Detailed preflight, publication and before/after integration receipts live in
|
||||||
|
`the-custodian/docs/evidence/2026-09-28-eso-*.json`. The earlier rollout failure
|
||||||
|
and rescue remain recorded; remediation does not count as unchanged success.
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,4 @@
|
||||||
# NOT included in kustomization: ESO v0.16.1 propagation must be fixed first.
|
# CUST-WP-0073: explicit ESO target metadata verified before re-enabling.
|
||||||
apiVersion: admissionregistration.k8s.io/v1
|
apiVersion: admissionregistration.k8s.io/v1
|
||||||
kind: ValidatingAdmissionPolicyBinding
|
kind: ValidatingAdmissionPolicyBinding
|
||||||
metadata:
|
metadata:
|
||||||
|
|
@ -2,3 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
resources:
|
resources:
|
||||||
- policy.yaml
|
- policy.yaml
|
||||||
|
- binding.yaml
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue