Record Core authorization boundary and pending GitOps tool projection
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
parent
743def17be
commit
ff34d596f9
2 changed files with 22 additions and 3 deletions
|
|
@ -12,9 +12,14 @@ identities. Public source reads need no repository credential. A general reposit
|
|||
write PAT cannot enforce image-only changes by itself: the executor must validate
|
||||
the exact before/after commits and authenticated receipts before writing, while
|
||||
protected branches and required checks prevent bypass. Restrict its repository
|
||||
membership to the release repository and its ArgoCD role to get/sync the single
|
||||
`activity-core/activity-core` application. No root sync, application spec updates,
|
||||
project updates, exec, prune, overrides, secrets or other applications.
|
||||
membership to the release repository and reconciliation to the single
|
||||
`activity-core/activity-core` application. This installation is ArgoCD Core:
|
||||
there is no ArgoCD API-server role/token lane to reuse. Kubernetes RBAC cannot
|
||||
restrict Application patch access to only the operation fields. Use a narrowly
|
||||
implemented sync broker with admission enforcement before granting such patch
|
||||
access; an Application-scoped Kubernetes Role alone is insufficient. No root-wide
|
||||
sync, arbitrary application spec updates, project updates, exec, prune, overrides,
|
||||
secrets or other applications.
|
||||
|
||||
The present parent Application pins the child's source revision in the platform
|
||||
repository. Therefore an app-only ArgoCD sync grant alone cannot perform durable
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue