Files
unkin-agent 2ec552d6fd
ci/woodpecker/push/apply Pipeline was successful
Add agent-observability kubernetes creds role and policy (#156)
No agent Vault role covers the VictoriaMetrics/VictoriaLogs stack, so a scoped Kubernetes token cannot be issued for it and writes there fall back to an admin context.

- add the agent-observability kubernetes secret backend role, allowed in vm-system, observability and logging
- add its generated role rules: read plus patch/update on VictoriaMetrics CRs and workloads, pod delete for rolling restarts, read-only on services, configmaps, endpoints, events and Gateway API routes
- add a policy granting update on kubernetes/au/syd1/creds/agent-observability to the cluster_operator LDAP group and the agents approle

Reviewed-on: #156
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-27 11:23:36 +10:00
..