Record Core authorization boundary and pending GitOps tool projection
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 6s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
codex 2026-09-27 16:01:33 +02:00
parent 743def17be
commit ff34d596f9
2 changed files with 22 additions and 3 deletions

View file

@ -12,9 +12,14 @@ identities. Public source reads need no repository credential. A general reposit
write PAT cannot enforce image-only changes by itself: the executor must validate
the exact before/after commits and authenticated receipts before writing, while
protected branches and required checks prevent bypass. Restrict its repository
membership to the release repository and its ArgoCD role to get/sync the single
`activity-core/activity-core` application. No root sync, application spec updates,
project updates, exec, prune, overrides, secrets or other applications.
membership to the release repository and reconciliation to the single
`activity-core/activity-core` application. This installation is ArgoCD Core:
there is no ArgoCD API-server role/token lane to reuse. Kubernetes RBAC cannot
restrict Application patch access to only the operation fields. Use a narrowly
implemented sync broker with admission enforcement before granting such patch
access; an Application-scoped Kubernetes Role alone is insufficient. No root-wide
sync, arbitrary application spec updates, project updates, exec, prune, overrides,
secrets or other applications.
The present parent Application pins the child's source revision in the platform
repository. Therefore an app-only ArgoCD sync grant alone cannot perform durable