fix(security): rebind annotation guard after ESO metadata remediation

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e7fb-275d-7db0-b1df-39ed943427da
This commit is contained in:
codex 2026-09-28 16:27:24 +02:00
parent d2631f6112
commit 7daf7e9067
3 changed files with 24 additions and 4 deletions

View file

@ -35,10 +35,10 @@ That version copies ExternalSecret metadata when no target template exists;
31 current ExternalSecrets have no template. Removing annotations from targets 31 current ExternalSecrets have no template. Removing annotations from targets
alone cannot stop the controller adding them back. All 39 ExternalSecrets alone cannot stop the controller adding them back. All 39 ExternalSecrets
recovered after binding deletion; failed controllers were explicitly refreshed. recovered after binding deletion; failed controllers were explicitly refreshed.
The policy remains installed but UNBOUND. `binding.pending.yaml` is deliberately The rollback revision `6016f72` left the policy UNBOUND and excluded the binding
absent from kustomization. No ordinary sync of this revision enables enforcement. from kustomization. That revision remains the immediate rollback target.
Before enabling: add explicit metadata templates in the 31 owning declarations, Re-enablement prerequisite: add explicit metadata templates in the 31 owning declarations,
preserving intended labels/annotations except last-applied; apply through owner preserving intended labels/annotations except last-applied; apply through owner
paths; verify actual ESO refresh with annotation-free target Secrets. Retain paths; verify actual ESO refresh with annotation-free target Secrets. Retain
existing data templates and remote references. Do not waive ESO from the policy existing data templates and remote references. Do not waive ESO from the policy
@ -54,3 +54,22 @@ Source for the diagnosed behavior:
https://github.com/external-secrets/external-secrets/blob/v0.16.1/pkg/controllers/externalsecret/externalsecret_controller_template.go https://github.com/external-secrets/external-secrets/blob/v0.16.1/pkg/controllers/externalsecret/externalsecret_controller_template.go
Detailed receipts: the-custodian/docs/evidence/2026-09-28-secret-annotation-*.json. Detailed receipts: the-custodian/docs/evidence/2026-09-28-secret-annotation-*.json.
## Corrected writer rollout
On September 28 the founder authorized continuing the 31-declaration correction.
Metadata-only templates are committed and published across the 12 owning repos.
Server dry-run proved all 31 changes preserve the remaining ExternalSecret spec.
Direct owner resources used metadata-only SSA; Target Revenue used a selective
Argo sync of its ExternalSecret, with no migration/bootstrap hooks. All 39
ExternalSecrets completed fresh successful refreshes before binding activation.
`binding.yaml` is included for the reviewed re-enablement. After syncing, repeat
the native admission proof and require all 39 ExternalSecrets to complete fresh
refreshes with the binding present. Keep the safe annotation scan receipt and
report the absent-namespace orphan separately. No Secret values are read or
rotated by the metadata maintenance. ESO uses its normal credential refresh path.
Detailed preflight, publication and before/after integration receipts live in
`the-custodian/docs/evidence/2026-09-28-eso-*.json`. The earlier rollout failure
and rescue remain recorded; remediation does not count as unchanged success.

View file

@ -1,4 +1,4 @@
# NOT included in kustomization: ESO v0.16.1 propagation must be fixed first. # CUST-WP-0073: explicit ESO target metadata verified before re-enabling.
apiVersion: admissionregistration.k8s.io/v1 apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicyBinding kind: ValidatingAdmissionPolicyBinding
metadata: metadata:

View file

@ -2,3 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization kind: Kustomization
resources: resources:
- policy.yaml - policy.yaml
- binding.yaml