Add logarchive gpg key and logging-namespace public-key read
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful

logarchiver encrypts archived logs to an OpenPGP key held in the gpg engine
so the private key never leaves Vault; retrieval delegates decryption back to
gpg/decrypt/logarchive. This provisions that key and lets the service read its
public key.

- Create gpg key logarchive (rsa-4096, non-exportable) in the gpg mount.
- Add k8s auth role logarchiver bound to the logarchiver ServiceAccount in the
  logging namespace.
- Add policy granting read on gpg/keys/logarchive to that role (public key only;
  no decrypt).

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
This commit is contained in:
benvin
2026-07-29 20:23:18 +10:00
parent 31f32aba0f
commit ea2f03558a
3 changed files with 27 additions and 0 deletions
@@ -0,0 +1,7 @@
bound_service_account_names:
- logarchiver
bound_service_account_namespaces:
- logging
token_ttl: 600
token_max_ttl: 600
audience: vault
+8
View File
@@ -0,0 +1,8 @@
# config/gpg_key/gpg/logarchive.yaml
# OpenPGP key in the gpg engine for the logarchiver service. The private key
# stays in Vault; logarchiver reads only the exported public key
# (gpg/keys/logarchive) to encrypt archived logs, and retrieval delegates
# decryption back to gpg/decrypt/logarchive. Key name = "logarchive", backend = "gpg".
algorithm: rsa-4096
identity: "logarchive <logarchive@unkin.net>"
exportable: false
+12
View File
@@ -0,0 +1,12 @@
# Allow the logarchiver service (logging namespace) to read the logarchive
# public key. A plain read on gpg/keys/<name> returns the armored public_key;
# no decrypt/export capability is granted.
---
rules:
- path: "gpg/keys/logarchive"
capabilities:
- read
auth:
k8s/au/syd1:
- logarchiver