Rework agent-dns to service_account_name mode against a static SA
Instead of generating cluster-wide RBAC, the agent-dns role now mints tokens for a static GitOps-managed service account (argocd-apps#332) whose per-namespace RoleBindings confine access to exactly the four bind namespaces. Ordering: the argocd-apps RBAC must sync before these creds are usable, since Vault mints tokens for an SA that must already exist. - extend the kubernetes_secret_backend_role module with an optional service_account_name; when set, generated_role_rules and kubernetes_role_type are omitted (the SA's own bindings supply RBAC). - switch the agent-dns role to service_account_name agent-dns with allowed_kubernetes_namespaces bind-system; drop its generated rules. Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
allowed_kubernetes_namespaces:
|
||||
- "*"
|
||||
kubernetes_role_type: "ClusterRole"
|
||||
- "bind-system"
|
||||
service_account_name: "agent-dns"
|
||||
extra_labels: {}
|
||||
|
||||
Reference in New Issue
Block a user