QONTO-WP-0004-T06. Requests a second, workload-scoped access lane into the existing tenants/binky/qonto-api credential (CCR-2026-0008 is human/OIDC admin access only, not usable by a running pod). Mirrors CCR-2026-0003's llm-connect pattern: External Secrets Operator reads the KV path into a namespace-scoped Kubernetes Secret via a ClusterSecretStore restricted to the new qonto-assistant namespace; the pod never touches the OpenBao token directly. Status: proposed, not approved -- requires platform-operator and binky-tenant-owner sign-off before the auth role/policy are applied. Draft ClusterSecretStore manifest included, following the same "deployed separately, not via this kustomization" pattern as the existing activity-core/forgejo/reuse stores. Validated against schemas/credential-change-request.schema.yaml. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| kustomization.yaml | ||
| openbao-activity-core.clustersecretstore.yaml | ||
| openbao-forgejo.clustersecretstore.yaml | ||
| openbao-qonto-assistant.clustersecretstore.yaml | ||
| openbao-reuse.clustersecretstore.yaml | ||
| openbao.clustersecretstore.yaml | ||