Add Vault-scoped agent kubernetes roles + agents AppRole
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful

Give agentic workloads domain-scoped kubernetes credentials so they stop
needing cluster-admin/root. Adds four least-privilege kubernetes secret
engine roles, an `agents` AppRole (role_id-only, CIDR-bound to the agent
workstation) that can mint them, and a write-capable KV grant for the
kubernetes secrets subtree.

- Add kubernetes_secret_backend_role configs agent-dhcp/dns/certs/storage
  with generated_role_rules scoping each to its operator CRDs + pod/log reads.
- Add creds policies for each role, bound to Ben's cluster-operator ldap
  group (human kubectl use) and the agents AppRole (programmatic use).
- Add the `agents` AppRole: bind_secret_id false, token_bound_cidrs
  10.10.12.200/32, deterministic role_id, 1h/4h TTLs.
- Add kv/kubernetes/agents policy granting the AppRole create/read/update/list
  on the kubernetes KV subtree (no delete).

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
This commit is contained in:
2026-08-02 21:29:18 +10:00
parent c0cc74927c
commit 41fef29bad
14 changed files with 195 additions and 0 deletions
@@ -0,0 +1,6 @@
token_ttl: 3600
token_max_ttl: 14400
bind_secret_id: false
token_bound_cidrs:
- "10.10.12.200/32"
use_deterministic_role_id: true
@@ -0,0 +1,4 @@
allowed_kubernetes_namespaces:
- "cert-manager"
kubernetes_role_type: "Role"
extra_labels: {}
@@ -0,0 +1,4 @@
allowed_kubernetes_namespaces:
- "dhcp-system"
kubernetes_role_type: "Role"
extra_labels: {}
@@ -0,0 +1,4 @@
allowed_kubernetes_namespaces:
- "*"
kubernetes_role_type: "ClusterRole"
extra_labels: {}
@@ -0,0 +1,4 @@
allowed_kubernetes_namespaces:
- "cephrgw-system"
kubernetes_role_type: "Role"
extra_labels: {}