Add agent-dns RBAC: static SA + ClusterRole + per-namespace RoleBindings #332

Merged
benvin merged 1 commits from benvin/agent-dns-rbac into main 2026-08-02 21:49:38 +10:00
Owner

Why

Vault's kubernetes secret engine will mint scoped tokens for a static `agent-dns` service account instead of generating cluster-wide RBAC, so agent DNS access is confined to exactly the bind namespaces. This is the GitOps half of the terraform-vault agent-dns role rework (PR unkin/terraform-vault#109). Ordering: this must sync before the Vault `agent-dns` creds are usable — Vault mints tokens for an SA that must already exist.

How

  • Add ServiceAccount `agent-dns` + ClusterRole `agent-dns` (definition only, no ClusterRoleBinding) in `bind-system`: full verbs on `bind.unkin.net` CRDs, get/list/watch pods/services/configmaps/events, get pods/log.
  • Add RoleBinding `agent-dns` in each of `bind-system`, `bind-internal`, `bind-external`, `externaldns`, binding the SA to the ClusterRole in that namespace — confining all access (reads included) to those four namespaces.

Whitelist note: the platform AppProject already permits ClusterRole/ClusterRoleBinding and all four namespace destinations, so no project change is needed.

https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT

## Why Vault's kubernetes secret engine will mint scoped tokens for a static \`agent-dns\` service account instead of generating cluster-wide RBAC, so agent DNS access is confined to exactly the bind namespaces. This is the GitOps half of the terraform-vault agent-dns role rework (PR unkin/terraform-vault#109). Ordering: this must sync before the Vault \`agent-dns\` creds are usable — Vault mints tokens for an SA that must already exist. ## How - Add ServiceAccount \`agent-dns\` + ClusterRole \`agent-dns\` (definition only, no ClusterRoleBinding) in \`bind-system\`: full verbs on \`bind.unkin.net\` CRDs, get/list/watch pods/services/configmaps/events, get pods/log. - Add RoleBinding \`agent-dns\` in each of \`bind-system\`, \`bind-internal\`, \`bind-external\`, \`externaldns\`, binding the SA to the ClusterRole in that namespace — confining all access (reads included) to those four namespaces. Whitelist note: the platform AppProject already permits ClusterRole/ClusterRoleBinding and all four namespace destinations, so no project change is needed. https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
unkinben added 1 commit 2026-08-02 21:41:48 +10:00
Add agent-dns RBAC: static SA + ClusterRole + per-namespace RoleBindings
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
65344d2523
Vault's kubernetes secret engine will mint scoped tokens for a static
service account instead of generating cluster-wide RBAC, so agent DNS
access is confined to exactly the bind namespaces. This is the GitOps
half of the terraform-vault agent-dns role rework; it must sync before
the Vault agent-dns creds are usable (Vault mints tokens for an SA that
must already exist).

- add ServiceAccount agent-dns + ClusterRole agent-dns (definition only,
  no ClusterRoleBinding) in bind-system: full verbs on bind.unkin.net
  CRDs, get/list/watch pods/services/configmaps/events, get pods/log.
- add RoleBinding agent-dns in bind-system, bind-internal, bind-external,
  externaldns, each binding the SA to the ClusterRole in that namespace.

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
benvin merged commit f1c3b9617f into main 2026-08-02 21:49:38 +10:00
benvin deleted branch benvin/agent-dns-rbac 2026-08-02 21:49:38 +10:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/argocd-apps#332