railiance-platform/argocd/platform-addons/openbao-secretstore
tegwick 63818fe498
Some checks failed
CI Smoke / host-smoke (push) Has been cancelled
CI Smoke / container-smoke (push) Has been cancelled
CCR-2026-0009: propose qonto-assistant workload KV read lane
QONTO-WP-0004-T06. Requests a second, workload-scoped access lane into
the existing tenants/binky/qonto-api credential (CCR-2026-0008 is
human/OIDC admin access only, not usable by a running pod). Mirrors
CCR-2026-0003's llm-connect pattern: External Secrets Operator reads
the KV path into a namespace-scoped Kubernetes Secret via a
ClusterSecretStore restricted to the new qonto-assistant namespace;
the pod never touches the OpenBao token directly.

Status: proposed, not approved -- requires platform-operator and
binky-tenant-owner sign-off before the auth role/policy are applied.
Draft ClusterSecretStore manifest included, following the same
"deployed separately, not via this kustomization" pattern as the
existing activity-core/forgejo/reuse stores. Validated against
schemas/credential-change-request.schema.yaml.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-24 00:24:16 +02:00
..
kustomization.yaml Fix openbao-secretstore ArgoCD health: coulombcore scope only 2026-07-08 15:41:04 +02:00
openbao-activity-core.clustersecretstore.yaml Support activity-core ISSUE_CORE_API_KEY ExternalSecret on railiance01 2026-07-08 00:04:59 +02:00
openbao-forgejo.clustersecretstore.yaml Point Forgejo ClusterSecretStore at live coulombcore OpenBao 2026-07-07 14:35:46 +02:00
openbao-qonto-assistant.clustersecretstore.yaml CCR-2026-0009: propose qonto-assistant workload KV read lane 2026-07-24 00:24:16 +02:00
openbao-reuse.clustersecretstore.yaml Activate reuse-surface runtime secrets OpenBao lane (CCR-2026-0005) 2026-07-07 22:34:34 +02:00
openbao.clustersecretstore.yaml Add ESO OpenBao GitOps add-ons 2026-06-25 20:08:36 +02:00