Add logarchive gpg key + logging_logarchiver read access #106

Merged
benvin merged 1 commits from benvin/logarchive-gpg-key into master 2026-07-29 20:39:41 +10:00
3 changed files with 27 additions and 0 deletions
@@ -0,0 +1,7 @@
bound_service_account_names:
- logarchiver
bound_service_account_namespaces:
- logging
token_ttl: 600
token_max_ttl: 600
audience: vault
+8
View File
@@ -0,0 +1,8 @@
# config/gpg_key/gpg/logarchive.yaml
# OpenPGP key in the gpg engine for the logarchiver service. The private key
# stays in Vault; logarchiver reads only the exported public key
# (gpg/keys/logarchive) to encrypt archived logs, and retrieval delegates
# decryption back to gpg/decrypt/logarchive. Key name = "logarchive", backend = "gpg".
algorithm: rsa-4096
identity: "logarchive <logarchive@unkin.net>"
exportable: false
+12
View File
@@ -0,0 +1,12 @@
# Allow the logarchiver service (logging namespace, SA logarchiver) to read the
# logarchive public key. A plain read on gpg/keys/logarchive returns the armored
# public_key; no decrypt/export capability is granted (decrypt stays operator-only).
---
rules:
- path: "gpg/keys/logarchive"
capabilities:
- read
auth:
k8s/au/syd1:
- logging_logarchiver