feat: add identity secrets

- add kubernetes auth role for identity namespace
- add policy to access openldap bootstrap credentials
This commit is contained in:
Ben Vincent 2026-02-15 13:01:06 +11:00
parent 3fb5a64a17
commit 90b765d713
2 changed files with 16 additions and 0 deletions

View File

@ -0,0 +1,6 @@
bound_service_account_names:
- default
bound_service_account_namespaces:
- identity
token_ttl: 60
audience: vault

View File

@ -0,0 +1,10 @@
# Allow reading Radarr configuration
---
rules:
- path: "kv/data/service/openldap/ldap_admin_password"
capabilities:
- read
auth:
k8s/au/syd1:
- identity