Vault's kubernetes secret engine will mint scoped tokens for a static
service account instead of generating cluster-wide RBAC, so agent DNS
access is confined to exactly the bind namespaces. This is the GitOps
half of the terraform-vault agent-dns role rework; it must sync before
the Vault agent-dns creds are usable (Vault mints tokens for an SA that
must already exist).
- add ServiceAccount agent-dns + ClusterRole agent-dns (definition only,
no ClusterRoleBinding) in bind-system: full verbs on bind.unkin.net
CRDs, get/list/watch pods/services/configmaps/events, get pods/log.
- add RoleBinding agent-dns in bind-system, bind-internal, bind-external,
externaldns, each binding the SA to the ClusterRole in that namespace.
Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT