Add agent-dns RBAC: static SA + ClusterRole + per-namespace RoleBindings
Vault's kubernetes secret engine will mint scoped tokens for a static service account instead of generating cluster-wide RBAC, so agent DNS access is confined to exactly the bind namespaces. This is the GitOps half of the terraform-vault agent-dns role rework; it must sync before the Vault agent-dns creds are usable (Vault mints tokens for an SA that must already exist). - add ServiceAccount agent-dns + ClusterRole agent-dns (definition only, no ClusterRoleBinding) in bind-system: full verbs on bind.unkin.net CRDs, get/list/watch pods/services/configmaps/events, get pods/log. - add RoleBinding agent-dns in bind-system, bind-internal, bind-external, externaldns, each binding the SA to the ClusterRole in that namespace. Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
This commit is contained in:
@@ -8,5 +8,6 @@ resources:
|
||||
# vendored here, so they never drift from the operator.
|
||||
- https://git.unkin.net/unkin/bind-operator/raw/tag/v0.2.6/config/crd/install.yaml
|
||||
- rbac.yaml
|
||||
- agent-dns-rbac.yaml
|
||||
- deployment.yaml
|
||||
- vpa.yaml
|
||||
|
||||
Reference in New Issue
Block a user