Add audit-core ESO policy and ClusterSecretStore for railiance01

KV store for the sender registry only. Database leases stay on the
OpenBao database engine and are consumed via VaultDynamicSecret in
audit-core. Not added to the coulombcore ArgoCD kustomization.
This commit is contained in:
codex 2026-08-13 00:58:58 +02:00
parent c642367d98
commit cac9947e3a
2 changed files with 59 additions and 0 deletions

View file

@ -0,0 +1,26 @@
# Least-privilege policy for the External Secrets Operator audit-core lane.
#
# Covers:
# - dynamic runtime PostgreSQL lease (database/creds/audit-core-runtime)
# - dynamic migration PostgreSQL lease (database/creds/audit-core-migration)
# - sender registry KV (platform/workloads/audit-core/senders)
#
# ClusterSecretStore openbao-audit-core is namespace-limited to audit-core.
# The runtime pod mounts only the runtime secret; the migrate Job mounts only
# the migration secret. This policy is the union ESO needs to vend both.
path "database/creds/audit-core-runtime" {
capabilities = ["read"]
}
path "database/creds/audit-core-migration" {
capabilities = ["read"]
}
path "platform/data/workloads/audit-core/senders" {
capabilities = ["read"]
}
path "platform/metadata/workloads/audit-core/senders" {
capabilities = ["read"]
}