Close RAILIANCE-WP-0015-T06 rapp credential-lane binding
Document the one recipe a new rapp uses to acquire runtime secrets: standing KV secrets bind through a CCR target.rapp, leases through grant rapp_id. Stamp the existing postgres grants and the qonto workload CCR. Gate, delivery, and revocation are unchanged.
This commit is contained in:
parent
6ab882cc44
commit
dfa6373985
10 changed files with 342 additions and 10 deletions
|
|
@ -52,6 +52,11 @@ secret_markers_rejected:
|
|||
- ghp_
|
||||
- sk-
|
||||
|
||||
# Optional. Set when this CCR is the runtime bind for a rapp (RAILIANCE-WP-0015-T06).
|
||||
# target.rapp is a rapp-* slug. It does not replace target.workload.
|
||||
optional_target_fields:
|
||||
- rapp
|
||||
|
||||
workload_kv_read:
|
||||
required:
|
||||
openbao:
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue