railiance-platform/argocd/platform-addons/openbao-secretstore/keycape-approval-clients.externalsecrets.yaml
codex 80e053988f
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 4s
KeyCape factor custody acceptance / acceptance (push) Successful in 10s
fix(security): prevent ESO copying source annotations (CUST-WP-0073)
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e7fb-275d-7db0-b1df-39ed943427da
2026-09-28 15:56:50 +02:00

54 lines
1.8 KiB
YAML

# CCR-2026-0017 / CCR-2026-0018 (KEY-WP-0013-T02, RPF-WP-0035-T05).
# KeyCape-side delivery of the two approval-engine confidential client secrets.
# The Kubernetes Secret key stays client-secret to match the live
# KEYCAPE_RAPP_QONTO_CLIENT_SECRET secretKeyRef shape; the OpenBao field is
# CLIENT_SECRET because KV field names are uppercase by platform convention.
#
# Apply only after the stores sync and inside the agreed attended rollout window;
# the KeyCape image that reads both environment names rolls out after these sync.
---
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: keycape-secrets-engine-approval-client
namespace: sso
spec:
refreshInterval: 5m
secretStoreRef:
kind: ClusterSecretStore
name: openbao-keycape-secrets-engine-approval
target:
# Explicit target metadata prevents ESO copying source last-applied annotations.
template:
metadata: {}
name: keycape-secrets-engine-approval-client
creationPolicy: Owner
deletionPolicy: Retain
data:
- secretKey: client-secret
remoteRef:
key: workloads/secrets-engine/approval-client
property: CLIENT_SECRET
---
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: keycape-approval-engine-operator-client
namespace: sso
spec:
refreshInterval: 5m
secretStoreRef:
kind: ClusterSecretStore
name: openbao-keycape-approval-engine-operator
target:
# Explicit target metadata prevents ESO copying source last-applied annotations.
template:
metadata: {}
name: keycape-approval-engine-operator-client
creationPolicy: Owner
deletionPolicy: Retain
data:
- secretKey: client-secret
remoteRef:
key: workloads/approval-engine/operator-client
property: CLIENT_SECRET