diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index 80fef2a..bc330a2 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -317,6 +317,6 @@ | task | STATE-WP-0083-T07 | done | — | workplans/STATE-WP-0083-forge-derived-projection-reset.md | | task | STATE-WP-0083-T08 | done | — | workplans/STATE-WP-0083-forge-derived-projection-reset.md | | task | STATE-WP-0084-T01 | done | — | workplans/STATE-WP-0084-forge-read-for-private-repositories.md | -| task | STATE-WP-0084-T02 | wait | — | workplans/STATE-WP-0084-forge-read-for-private-repositories.md | -| task | STATE-WP-0084-T03 | wait | — | workplans/STATE-WP-0084-forge-read-for-private-repositories.md | +| task | STATE-WP-0084-T02 | progress | — | workplans/STATE-WP-0084-forge-read-for-private-repositories.md | +| task | STATE-WP-0084-T03 | progress | — | workplans/STATE-WP-0084-forge-read-for-private-repositories.md | | task | STATE-WP-0084-T04 | wait | — | workplans/STATE-WP-0084-forge-read-for-private-repositories.md | diff --git a/deploy/railiance/apps/charts/state-hub/templates/deployment.yaml b/deploy/railiance/apps/charts/state-hub/templates/deployment.yaml index d91989b..b6139af 100644 --- a/deploy/railiance/apps/charts/state-hub/templates/deployment.yaml +++ b/deploy/railiance/apps/charts/state-hub/templates/deployment.yaml @@ -52,7 +52,9 @@ spec: sources: - serviceAccountToken: path: token - audience: {{ .Values.forgeRead.openbao.audience | quote }} + {{- with .Values.forgeRead.openbao.audience }} + audience: {{ . | quote }} + {{- end }} expirationSeconds: {{ .Values.forgeRead.openbao.expirationSeconds }} {{- end }} {{- end }} @@ -111,6 +113,8 @@ spec: value: {{ .Values.forgeRead.openbao.addr | quote }} - name: OPENBAO_K8S_ROLE value: {{ .Values.forgeRead.openbao.role | quote }} + - name: OPENBAO_K8S_AUTH_MOUNT + value: {{ .Values.forgeRead.openbao.authMount | quote }} - name: OPENBAO_K8S_TOKEN_PATH value: /var/run/secrets/openbao/token - name: FORGE_READ_SECRET_PATH diff --git a/deploy/railiance/apps/charts/state-hub/values.yaml b/deploy/railiance/apps/charts/state-hub/values.yaml index 0ec45e9..ffa9a81 100644 --- a/deploy/railiance/apps/charts/state-hub/values.yaml +++ b/deploy/railiance/apps/charts/state-hub/values.yaml @@ -51,12 +51,27 @@ secret: forgeRead: enabled: false openbao: - addr: "" + # Matches every existing ClusterSecretStore on this cluster. + addr: http://openbao.openbao.svc:8200 + authMount: kubernetes role: state-hub-forge-derivation - audience: openbao + # KV v2: the read path carries the `data/` infix, mount `platform`. + secretPath: platform/data/workloads/state-hub/forge-derivation + secretKey: FORGE_READ_TOKEN + # Audience for the projected ServiceAccount token. + # + # Empty renders no audience, giving the token the API server's audience — + # what the four existing external-secrets roles use, and what an OpenBao + # Kubernetes auth role with no bound audience will accept. A token with an + # audience the role does not bind is rejected at TokenReview, so this must + # not be set to "openbao" until the role binds that audience. + # + # Worth revisiting: with no audience, a copy of this token is a credential + # for the cluster API. Binding `openbao` on the role and setting it here + # narrows it to OpenBao alone. Either way the token is short-lived and + # kubelet-rotated, which the legacy auto-mounted token is not. + audience: "" expirationSeconds: 3600 - secretPath: "" - secretKey: token resources: requests: diff --git a/deploy/railiance/apps/helm/state-hub-values.yaml b/deploy/railiance/apps/helm/state-hub-values.yaml index f37183d..923cf72 100644 --- a/deploy/railiance/apps/helm/state-hub-values.yaml +++ b/deploy/railiance/apps/helm/state-hub-values.yaml @@ -50,3 +50,9 @@ sweep: hostname: 239.62.205.92.host.secureserver.net hostPath: /home/tegwick sshHostPath: /home/tegwick/.ssh + +# Forge read credential (STATE-WP-0084-T02). Coordinates only — the token lives +# in OpenBao at platform/workloads/state-hub/forge-derivation and reaches the +# pod through Kubernetes auth, never through this file or a Secret. +forgeRead: + enabled: true