65344d2523
Vault's kubernetes secret engine will mint scoped tokens for a static service account instead of generating cluster-wide RBAC, so agent DNS access is confined to exactly the bind namespaces. This is the GitOps half of the terraform-vault agent-dns role rework; it must sync before the Vault agent-dns creds are usable (Vault mints tokens for an SA that must already exist). - add ServiceAccount agent-dns + ClusterRole agent-dns (definition only, no ClusterRoleBinding) in bind-system: full verbs on bind.unkin.net CRDs, get/list/watch pods/services/configmaps/events, get pods/log. - add RoleBinding agent-dns in bind-system, bind-internal, bind-external, externaldns, each binding the SA to the ClusterRole in that namespace. Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
17 lines
395 B
YAML
17 lines
395 B
YAML
---
|
|
# Confines the agent-dns service account (in bind-system) to the agent-dns
|
|
# ClusterRole within this namespace.
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
kind: RoleBinding
|
|
metadata:
|
|
name: agent-dns
|
|
namespace: externaldns
|
|
subjects:
|
|
- kind: ServiceAccount
|
|
name: agent-dns
|
|
namespace: bind-system
|
|
roleRef:
|
|
apiGroup: rbac.authorization.k8s.io
|
|
kind: ClusterRole
|
|
name: agent-dns
|