Add Vault-scoped agent kubernetes roles + agents AppRole
Give agentic workloads domain-scoped kubernetes credentials so they stop needing cluster-admin/root. Adds four least-privilege kubernetes secret engine roles, an `agents` AppRole (role_id-only, CIDR-bound to the agent workstation) that can mint them, and a write-capable KV grant for the kubernetes secrets subtree. - Add kubernetes_secret_backend_role configs agent-dhcp/dns/certs/storage with generated_role_rules scoping each to its operator CRDs + pod/log reads. - Add creds policies for each role, bound to Ben's cluster-operator ldap group (human kubectl use) and the agents AppRole (programmatic use). - Add the `agents` AppRole: bind_secret_id false, token_bound_cidrs 10.10.12.200/32, deterministic role_id, 1h/4h TTLs. - Add kv/kubernetes/agents policy granting the AppRole create/read/update/list on the kubernetes KV subtree (no delete). Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
This commit is contained in:
@@ -0,0 +1,6 @@
|
||||
token_ttl: 3600
|
||||
token_max_ttl: 14400
|
||||
bind_secret_id: false
|
||||
token_bound_cidrs:
|
||||
- "10.10.12.200/32"
|
||||
use_deterministic_role_id: true
|
||||
@@ -0,0 +1,4 @@
|
||||
allowed_kubernetes_namespaces:
|
||||
- "cert-manager"
|
||||
kubernetes_role_type: "Role"
|
||||
extra_labels: {}
|
||||
@@ -0,0 +1,4 @@
|
||||
allowed_kubernetes_namespaces:
|
||||
- "dhcp-system"
|
||||
kubernetes_role_type: "Role"
|
||||
extra_labels: {}
|
||||
@@ -0,0 +1,4 @@
|
||||
allowed_kubernetes_namespaces:
|
||||
- "*"
|
||||
kubernetes_role_type: "ClusterRole"
|
||||
extra_labels: {}
|
||||
@@ -0,0 +1,4 @@
|
||||
allowed_kubernetes_namespaces:
|
||||
- "cephrgw-system"
|
||||
kubernetes_role_type: "Role"
|
||||
extra_labels: {}
|
||||
@@ -0,0 +1,12 @@
|
||||
# Allow access to agent-certs Kubernetes credentials
|
||||
---
|
||||
rules:
|
||||
- path: "kubernetes/au/syd1/creds/agent-certs"
|
||||
capabilities:
|
||||
- update
|
||||
|
||||
auth:
|
||||
ldap:
|
||||
- kubernetes_au_syd1_cluster_operator
|
||||
approle:
|
||||
- agents
|
||||
@@ -0,0 +1,12 @@
|
||||
# Allow access to agent-dhcp Kubernetes credentials
|
||||
---
|
||||
rules:
|
||||
- path: "kubernetes/au/syd1/creds/agent-dhcp"
|
||||
capabilities:
|
||||
- update
|
||||
|
||||
auth:
|
||||
ldap:
|
||||
- kubernetes_au_syd1_cluster_operator
|
||||
approle:
|
||||
- agents
|
||||
@@ -0,0 +1,12 @@
|
||||
# Allow access to agent-dns Kubernetes credentials
|
||||
---
|
||||
rules:
|
||||
- path: "kubernetes/au/syd1/creds/agent-dns"
|
||||
capabilities:
|
||||
- update
|
||||
|
||||
auth:
|
||||
ldap:
|
||||
- kubernetes_au_syd1_cluster_operator
|
||||
approle:
|
||||
- agents
|
||||
@@ -0,0 +1,12 @@
|
||||
# Allow access to agent-storage Kubernetes credentials
|
||||
---
|
||||
rules:
|
||||
- path: "kubernetes/au/syd1/creds/agent-storage"
|
||||
capabilities:
|
||||
- update
|
||||
|
||||
auth:
|
||||
ldap:
|
||||
- kubernetes_au_syd1_cluster_operator
|
||||
approle:
|
||||
- agents
|
||||
@@ -0,0 +1,17 @@
|
||||
# Allow the agents AppRole to manage the kubernetes KV subtree (no delete)
|
||||
---
|
||||
rules:
|
||||
- path: "kv/data/kubernetes/*"
|
||||
capabilities:
|
||||
- create
|
||||
- read
|
||||
- update
|
||||
- list
|
||||
- path: "kv/metadata/kubernetes/*"
|
||||
capabilities:
|
||||
- read
|
||||
- list
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- agents
|
||||
@@ -0,0 +1,33 @@
|
||||
---
|
||||
rules:
|
||||
- apiGroups:
|
||||
- "cert-manager.io"
|
||||
- "acme.cert-manager.io"
|
||||
resources:
|
||||
- "*"
|
||||
verbs:
|
||||
- "*"
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- "secrets"
|
||||
verbs:
|
||||
- "get"
|
||||
- "list"
|
||||
- "watch"
|
||||
- "delete"
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- "pods"
|
||||
verbs:
|
||||
- "get"
|
||||
- "list"
|
||||
- "watch"
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- "pods/log"
|
||||
verbs:
|
||||
- "get"
|
||||
- "list"
|
||||
@@ -0,0 +1,26 @@
|
||||
---
|
||||
rules:
|
||||
- apiGroups:
|
||||
- "kea.unkin.net"
|
||||
resources:
|
||||
- "*"
|
||||
verbs:
|
||||
- "*"
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- "pods"
|
||||
- "services"
|
||||
- "configmaps"
|
||||
- "events"
|
||||
verbs:
|
||||
- "get"
|
||||
- "list"
|
||||
- "watch"
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- "pods/log"
|
||||
verbs:
|
||||
- "get"
|
||||
- "list"
|
||||
@@ -0,0 +1,26 @@
|
||||
---
|
||||
rules:
|
||||
- apiGroups:
|
||||
- "bind.unkin.net"
|
||||
resources:
|
||||
- "*"
|
||||
verbs:
|
||||
- "*"
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- "pods"
|
||||
- "services"
|
||||
- "configmaps"
|
||||
- "events"
|
||||
verbs:
|
||||
- "get"
|
||||
- "list"
|
||||
- "watch"
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- "pods/log"
|
||||
verbs:
|
||||
- "get"
|
||||
- "list"
|
||||
@@ -0,0 +1,23 @@
|
||||
---
|
||||
rules:
|
||||
- apiGroups:
|
||||
- "ceph.unkin.net"
|
||||
resources:
|
||||
- "*"
|
||||
verbs:
|
||||
- "*"
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- "pods"
|
||||
verbs:
|
||||
- "get"
|
||||
- "list"
|
||||
- "watch"
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- "pods/log"
|
||||
verbs:
|
||||
- "get"
|
||||
- "list"
|
||||
Reference in New Issue
Block a user