Ben Vincent 65344d2523
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
Add agent-dns RBAC: static SA + ClusterRole + per-namespace RoleBindings
Vault's kubernetes secret engine will mint scoped tokens for a static
service account instead of generating cluster-wide RBAC, so agent DNS
access is confined to exactly the bind namespaces. This is the GitOps
half of the terraform-vault agent-dns role rework; it must sync before
the Vault agent-dns creds are usable (Vault mints tokens for an SA that
must already exist).

- add ServiceAccount agent-dns + ClusterRole agent-dns (definition only,
  no ClusterRoleBinding) in bind-system: full verbs on bind.unkin.net
  CRDs, get/list/watch pods/services/configmaps/events, get pods/log.
- add RoleBinding agent-dns in bind-system, bind-internal, bind-external,
  externaldns, each binding the SA to the ClusterRole in that namespace.

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
2026-08-02 21:41:32 +10:00
2026-03-01 16:34:01 +11:00

argocd-apps docs

Operational notes for the manifests in this repo.

Doc What it covers
cnpg-backups.md How CNPG Postgres backups (WAL archiving + nightly base backups) to Ceph RGW are configured.
cnpg-restore.md Restoring a CNPG cluster: full recovery, point-in-time recovery, cutover, and gotchas.
authentik-rancher-sso.md Manual runtime step to point Rancher's OIDC auth at the canonical identity.unkin.net issuer and trust the internal CA.
gitea-migration.md Staged cutover of the git.unkin.net forge from the Puppet VM to the gitea namespace.
S
Description
GitOps for ArgoCD
Readme 4.7 MiB
Languages
Shell 88.8%
Makefile 11.2%