Instead of generating cluster-wide RBAC, the agent-dns role now mints
tokens for a static GitOps-managed service account (argocd-apps#332)
whose per-namespace RoleBindings confine access to exactly the four bind
namespaces. Ordering: the argocd-apps RBAC must sync before these creds
are usable, since Vault mints tokens for an SA that must already exist.
- extend the kubernetes_secret_backend_role module with an optional
service_account_name; when set, generated_role_rules and
kubernetes_role_type are omitted (the SA's own bindings supply RBAC).
- switch the agent-dns role to service_account_name agent-dns with
allowed_kubernetes_namespaces bind-system; drop its generated rules.
Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
Give agentic workloads domain-scoped kubernetes credentials so they stop
needing cluster-admin/root. Adds four least-privilege kubernetes secret
engine roles, an `agents` AppRole (role_id-only, CIDR-bound to the agent
workstation) that can mint them, and a write-capable KV grant for the
kubernetes secrets subtree.
- Add kubernetes_secret_backend_role configs agent-dhcp/dns/certs/storage
with generated_role_rules scoping each to its operator CRDs + pod/log reads.
- Add creds policies for each role, bound to Ben's cluster-operator ldap
group (human kubectl use) and the agents AppRole (programmatic use).
- Add the `agents` AppRole: bind_secret_id false, token_bound_cidrs
10.10.12.200/32, deterministic role_id, 1h/4h TTLs.
- Add kv/kubernetes/agents policy granting the AppRole create/read/update/list
on the kubernetes KV subtree (no delete).
Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT