ghp: use the estate templated default Vault convention
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful

Drop the bespoke ghp SA/role/policy (terraform-vault#120 closed). The default
k8s auth role, bound to SA default in every namespace, already has a templated
read grant on kv/kubernetes/namespace/<ns>/default/*, so ghp needs zero
terraform-vault change.

- Remove the custom ServiceAccount; run as the namespace default SA.
- Deployment + migrate Job: serviceAccountName default.
- VaultAuth: role/serviceAccount default (mirrors artifactapi).
- VaultStaticSecrets: source paths move to the templated location
  kubernetes/namespace/ghp/default/{github-app,app}; Secret names unchanged.
This commit is contained in:
2026-08-13 20:01:43 +10:00
parent 42c1794d0e
commit 5faaff8d19
6 changed files with 12 additions and 18 deletions
+1 -1
View File
@@ -23,7 +23,7 @@ spec:
labels:
app: ghp
spec:
serviceAccountName: ghp
serviceAccountName: default
automountServiceAccountToken: true
securityContext:
runAsNonRoot: true