fix: kubernetes auth fixes
- annotations as alias metadata does not work with openbao (idempotency issue) - set token_ttl to be 600 for all auth roles for kubernetes (min)
This commit is contained in:
parent
4b176846f2
commit
c093d5830d
@ -1,5 +1,5 @@
|
||||
kubernetes_host: https://api-k8s.service.consul:6443
|
||||
disable_iss_validation: true
|
||||
use_annotations_as_alias_metadata: true
|
||||
use_annotations_as_alias_metadata: false # doesnt work with openbao yet
|
||||
default_lease_ttl: 1h
|
||||
max_lease_ttl: 24h
|
||||
|
||||
@ -4,5 +4,5 @@ bound_service_account_names:
|
||||
bound_service_account_namespaces:
|
||||
- csi-cephrbd
|
||||
- csi-cephfs
|
||||
token_ttl: 60
|
||||
token_ttl: 600
|
||||
audience: vault
|
||||
|
||||
@ -2,5 +2,5 @@ bound_service_account_names:
|
||||
- cert-manager-vault-issuer
|
||||
bound_service_account_namespaces:
|
||||
- cert-manager
|
||||
token_ttl: 60
|
||||
token_ttl: 600
|
||||
audience: vault
|
||||
|
||||
@ -2,5 +2,5 @@ bound_service_account_names:
|
||||
- externaldns
|
||||
bound_service_account_namespaces:
|
||||
- externaldns
|
||||
token_ttl: 60
|
||||
token_ttl: 600
|
||||
audience: vault
|
||||
|
||||
@ -2,5 +2,5 @@ bound_service_account_names:
|
||||
- default
|
||||
bound_service_account_namespaces:
|
||||
- huntarr
|
||||
token_ttl: 60
|
||||
token_ttl: 600
|
||||
audience: vault
|
||||
|
||||
@ -2,5 +2,5 @@ bound_service_account_names:
|
||||
- default
|
||||
bound_service_account_namespaces:
|
||||
- identity
|
||||
token_ttl: 60
|
||||
token_ttl: 600
|
||||
audience: vault
|
||||
|
||||
@ -2,5 +2,5 @@ bound_service_account_names:
|
||||
- media-apps-vault-reader
|
||||
bound_service_account_namespaces:
|
||||
- media-apps
|
||||
token_ttl: 60
|
||||
token_ttl: 600
|
||||
audience: vault
|
||||
|
||||
@ -2,5 +2,5 @@ bound_service_account_names:
|
||||
- default
|
||||
bound_service_account_namespaces:
|
||||
- puppet
|
||||
token_ttl: 60
|
||||
token_ttl: 600
|
||||
audience: vault
|
||||
|
||||
@ -2,5 +2,5 @@ bound_service_account_names:
|
||||
- rancher
|
||||
bound_service_account_namespaces:
|
||||
- cattle-system
|
||||
token_ttl: 60
|
||||
token_ttl: 600
|
||||
audience: vault
|
||||
|
||||
@ -2,5 +2,5 @@ bound_service_account_names:
|
||||
- default
|
||||
bound_service_account_namespaces:
|
||||
- repoflow
|
||||
token_ttl: 60
|
||||
token_ttl: 600
|
||||
audience: vault
|
||||
|
||||
Loading…
Reference in New Issue
Block a user