vault's terraform approle doesnt need to access all of these kubernetes roles, it was just added as a placeholder and access to the kubernetes roles was via the `vault_admin` to-much-access account. this is an effort to roll back that and make access more targeted. - add kubernetes* ldap groups for specific cluster/role combinations - remove tf_vault from kubernetes* roles |
||
|---|---|---|
| .. | ||
| kubernetes_au_syd1_cluster_admin.yaml | ||
| kubernetes_au_syd1_cluster_operator.yaml | ||
| kubernetes_au_syd1_cluster_root.yaml | ||
| vault_admin.yaml | ||