Add audit-core ESO policy and ClusterSecretStore for railiance01
KV store for the sender registry only. Database leases stay on the OpenBao database engine and are consumed via VaultDynamicSecret in audit-core. Not added to the coulombcore ArgoCD kustomization.
This commit is contained in:
parent
c642367d98
commit
cac9947e3a
2 changed files with 59 additions and 0 deletions
|
|
@ -0,0 +1,33 @@
|
|||
# audit-core sender-registry store. Deploy on railiance01 (not the
|
||||
# coulombcore ArgoCD kustomization — same interim pattern as
|
||||
# openbao-email-connect / openbao-activity-core).
|
||||
#
|
||||
# Prereq: Secret external-secrets/openbao-audit-core-eso-token (key: token)
|
||||
# with policy external-secrets-audit-core. Bootstrap:
|
||||
# audit-core/scripts/openbao-eso-token-apply.sh
|
||||
#
|
||||
# Database leases are *not* served by this store. They are OpenBao database
|
||||
# engine credentials and are vended by VaultDynamicSecret in the audit-core
|
||||
# package (deploy/vaultdynamicsecrets.yaml).
|
||||
apiVersion: external-secrets.io/v1
|
||||
kind: ClusterSecretStore
|
||||
metadata:
|
||||
name: openbao-audit-core
|
||||
labels:
|
||||
app.kubernetes.io/part-of: railiance-gitops
|
||||
railiance-platform/component: external-secrets
|
||||
app.kubernetes.io/name: audit-core
|
||||
spec:
|
||||
provider:
|
||||
vault:
|
||||
server: http://openbao.openbao.svc:8200
|
||||
path: platform
|
||||
version: v2
|
||||
auth:
|
||||
tokenSecretRef:
|
||||
name: openbao-audit-core-eso-token
|
||||
namespace: external-secrets
|
||||
key: token
|
||||
conditions:
|
||||
- namespaces:
|
||||
- audit-core
|
||||
26
openbao/policies/external-secrets-audit-core.hcl
Normal file
26
openbao/policies/external-secrets-audit-core.hcl
Normal file
|
|
@ -0,0 +1,26 @@
|
|||
# Least-privilege policy for the External Secrets Operator audit-core lane.
|
||||
#
|
||||
# Covers:
|
||||
# - dynamic runtime PostgreSQL lease (database/creds/audit-core-runtime)
|
||||
# - dynamic migration PostgreSQL lease (database/creds/audit-core-migration)
|
||||
# - sender registry KV (platform/workloads/audit-core/senders)
|
||||
#
|
||||
# ClusterSecretStore openbao-audit-core is namespace-limited to audit-core.
|
||||
# The runtime pod mounts only the runtime secret; the migrate Job mounts only
|
||||
# the migration secret. This policy is the union ESO needs to vend both.
|
||||
|
||||
path "database/creds/audit-core-runtime" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
|
||||
path "database/creds/audit-core-migration" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
|
||||
path "platform/data/workloads/audit-core/senders" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
|
||||
path "platform/metadata/workloads/audit-core/senders" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue