Add Vault-scoped agent kubernetes roles + agents AppRole #109

Merged
benvin merged 2 commits from benvin/agent-kube-contexts into master 2026-08-02 21:55:06 +10:00

2 Commits

Author SHA1 Message Date
unkinben 680a0455e5 Rework agent-dns to service_account_name mode against a static SA
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
Instead of generating cluster-wide RBAC, the agent-dns role now mints
tokens for a static GitOps-managed service account (argocd-apps#332)
whose per-namespace RoleBindings confine access to exactly the four bind
namespaces. Ordering: the argocd-apps RBAC must sync before these creds
are usable, since Vault mints tokens for an SA that must already exist.

- extend the kubernetes_secret_backend_role module with an optional
  service_account_name; when set, generated_role_rules and
  kubernetes_role_type are omitted (the SA's own bindings supply RBAC).
- switch the agent-dns role to service_account_name agent-dns with
  allowed_kubernetes_namespaces bind-system; drop its generated rules.

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
2026-08-02 21:45:26 +10:00
unkinben 41fef29bad Add Vault-scoped agent kubernetes roles + agents AppRole
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
Give agentic workloads domain-scoped kubernetes credentials so they stop
needing cluster-admin/root. Adds four least-privilege kubernetes secret
engine roles, an `agents` AppRole (role_id-only, CIDR-bound to the agent
workstation) that can mint them, and a write-capable KV grant for the
kubernetes secrets subtree.

- Add kubernetes_secret_backend_role configs agent-dhcp/dns/certs/storage
  with generated_role_rules scoping each to its operator CRDs + pod/log reads.
- Add creds policies for each role, bound to Ben's cluster-operator ldap
  group (human kubectl use) and the agents AppRole (programmatic use).
- Add the `agents` AppRole: bind_secret_id false, token_bound_cidrs
  10.10.12.200/32, deterministic role_id, 1h/4h TTLs.
- Add kv/kubernetes/agents policy granting the AppRole create/read/update/list
  on the kubernetes KV subtree (no delete).

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
2026-08-02 21:29:18 +10:00