railiance-platform/argocd
tegwick 63818fe498
Some checks failed
CI Smoke / host-smoke (push) Has been cancelled
CI Smoke / container-smoke (push) Has been cancelled
CCR-2026-0009: propose qonto-assistant workload KV read lane
QONTO-WP-0004-T06. Requests a second, workload-scoped access lane into
the existing tenants/binky/qonto-api credential (CCR-2026-0008 is
human/OIDC admin access only, not usable by a running pod). Mirrors
CCR-2026-0003's llm-connect pattern: External Secrets Operator reads
the KV path into a namespace-scoped Kubernetes Secret via a
ClusterSecretStore restricted to the new qonto-assistant namespace;
the pod never touches the OpenBao token directly.

Status: proposed, not approved -- requires platform-operator and
binky-tenant-owner sign-off before the auth role/policy are applied.
Draft ClusterSecretStore manifest included, following the same
"deployed separately, not via this kustomization" pattern as the
existing activity-core/forgejo/reuse stores. Validated against
schemas/credential-change-request.schema.yaml.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-24 00:24:16 +02:00
..
applications Repoint ArgoCD GitOps to Forgejo (RAIL-HO-WP-0005 T11) 2026-07-08 15:35:28 +02:00
bootstrap Point npm handoff and ArgoCD sourceRepos at Forgejo 2026-07-09 11:38:14 +02:00
platform-addons/openbao-secretstore CCR-2026-0009: propose qonto-assistant workload KV read lane 2026-07-24 00:24:16 +02:00
repositories Repoint ArgoCD GitOps to Forgejo (RAIL-HO-WP-0005 T11) 2026-07-08 15:35:28 +02:00