Prepare bounded Kubernetes authentication recovery for three ESO lanes

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
codex 2026-09-05 18:38:19 +02:00
parent 5d6d8724b4
commit bd2e6e86b8
11 changed files with 372 additions and 37 deletions

View file

@ -1,11 +1,4 @@
# reuse-surface uses the private OpenBao service on railiance01. Public
# bao.coulomb.social remains the operator/API address and is not a workload
# runtime dependency.
#
# Prereq: Secret external-secrets/openbao-reuse-eso-token (key: token) with a
# policy-limited OpenBao token that can read
# platform/workloads/reuse/reuse-surface/runtime-secrets.
# Bootstrap: railiance-apps make reuse-openbao-eso-token-apply
# RPF-WP-0037: exact namespace/SA/audience Kubernetes auth; no static token.
apiVersion: external-secrets.io/v1beta1
kind: ClusterSecretStore
metadata:
@ -20,10 +13,14 @@ spec:
path: platform
version: v2
auth:
tokenSecretRef:
name: openbao-reuse-eso-token
namespace: external-secrets
key: token
kubernetes:
mountPath: kubernetes
role: reuse-surface-runtime-eso
serviceAccountRef:
name: reuse-surface-eso
namespace: reuse
audiences:
- openbao
conditions:
- namespaces:
- reuse
- namespaces:
- reuse