e6e882abfc
The Vault KV layout is kubernetes/namespace/<ns>/<sa>/<secret>, so vlogs and logviewer both running as SA default in the shared logging namespace would collide on one oauth-credentials entry. Splitting vlogs out resolves it without widening any Vault policy. - Move apps/base/logging/vlogs to apps/base/vlogs, namespace vlogs - Add namespace.yaml and a vlogs-scoped VaultAuth (role default) - Point the VaultStaticSecret at kubernetes/namespace/vlogs/default/oauth-credentials - Add the au-syd1 overlay, platform ApplicationSet path and project destination - Move the wildcard-unkin-net-tls reflection from logging to vlogs; vlogs was its only consumer there Secret is already seeded at the new Vault path. Reviewed-on: #507 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
18 lines
376 B
YAML
18 lines
376 B
YAML
---
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultStaticSecret
|
|
metadata:
|
|
name: vlogs-oauth-credentials
|
|
namespace: vlogs
|
|
spec:
|
|
destination:
|
|
create: true
|
|
name: vlogs-oauth-credentials
|
|
overwrite: true
|
|
hmacSecretData: true
|
|
mount: kv
|
|
path: kubernetes/namespace/vlogs/default/oauth-credentials
|
|
refreshAfter: 5m
|
|
type: kv-v2
|
|
vaultAuthRef: default
|