Files
unkinben ea380b9417
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
Add cert-manager clouddns KV read access for VSO
cert-manager needs a Google Cloud DNS service-account key to solve
Let's Encrypt DNS-01 challenges for publicly-trusted certs. VSO syncs it
from Vault KV, so the cert-manager namespace needs its own k8s auth role
and a policy granting read on the KV path.

- Add k8s auth role cert_manager_clouddns bound to SA
  cert-manager-clouddns in the cert-manager namespace.
- Add policy granting read on
  kv/service/kubernetes/au/syd1/cert-manager/clouddns, bound to that role.

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
2026-08-02 17:04:32 +10:00
..
2026-05-21 23:52:30 +10:00
2026-05-21 23:52:30 +10:00
2026-05-21 23:52:30 +10:00
2026-05-21 23:52:30 +10:00
2026-05-21 23:52:30 +10:00
2026-05-21 23:52:30 +10:00
2026-05-21 23:52:30 +10:00
2026-05-21 23:52:30 +10:00