feat(forge): point the credential lane at the built OpenBao objects
MASON-WP-0003-T02 delivered the token on 2026-08-27, and three of its details differ from the chart's placeholders: KV v2 puts `data/` in the read path, the field is `FORGE_READ_TOKEN` rather than `token`, and the address matches every existing ClusterSecretStore (`http://openbao.openbao.svc:8200`, mount `platform`, auth mount `kubernetes`). The projected token's audience is now optional and defaults to empty. A token carrying an audience the auth role does not bind is rejected at TokenReview, and the role's audience binding is not readable without a privileged session — the four existing external-secrets roles use the API server audience, so that is the default that can be verified to work. Setting `openbao` here narrows the token to OpenBao alone and is worth doing once the role binds it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 2583210@bnt-lap001 Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
This commit is contained in:
parent
550a523435
commit
11f689d86d
4 changed files with 32 additions and 7 deletions
|
|
@ -50,3 +50,9 @@ sweep:
|
|||
hostname: 239.62.205.92.host.secureserver.net
|
||||
hostPath: /home/tegwick
|
||||
sshHostPath: /home/tegwick/.ssh
|
||||
|
||||
# Forge read credential (STATE-WP-0084-T02). Coordinates only — the token lives
|
||||
# in OpenBao at platform/workloads/state-hub/forge-derivation and reaches the
|
||||
# pod through Kubernetes auth, never through this file or a Secret.
|
||||
forgeRead:
|
||||
enabled: true
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue