65344d252371427a3ffe94fc5a6afb92778dcd1d
Vault's kubernetes secret engine will mint scoped tokens for a static service account instead of generating cluster-wide RBAC, so agent DNS access is confined to exactly the bind namespaces. This is the GitOps half of the terraform-vault agent-dns role rework; it must sync before the Vault agent-dns creds are usable (Vault mints tokens for an SA that must already exist). - add ServiceAccount agent-dns + ClusterRole agent-dns (definition only, no ClusterRoleBinding) in bind-system: full verbs on bind.unkin.net CRDs, get/list/watch pods/services/configmaps/events, get pods/log. - add RoleBinding agent-dns in bind-system, bind-internal, bind-external, externaldns, each binding the SA to the ClusterRole in that namespace. Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
argocd-apps docs
Operational notes for the manifests in this repo.
| Doc | What it covers |
|---|---|
| cnpg-backups.md | How CNPG Postgres backups (WAL archiving + nightly base backups) to Ceph RGW are configured. |
| cnpg-restore.md | Restoring a CNPG cluster: full recovery, point-in-time recovery, cutover, and gotchas. |
| authentik-rancher-sso.md | Manual runtime step to point Rancher's OIDC auth at the canonical identity.unkin.net issuer and trust the internal CA. |
| gitea-migration.md | Staged cutover of the git.unkin.net forge from the Puppet VM to the gitea namespace. |
Description
Languages
Shell
88.8%
Makefile
11.2%