41fef29bad
Give agentic workloads domain-scoped kubernetes credentials so they stop needing cluster-admin/root. Adds four least-privilege kubernetes secret engine roles, an `agents` AppRole (role_id-only, CIDR-bound to the agent workstation) that can mint them, and a write-capable KV grant for the kubernetes secrets subtree. - Add kubernetes_secret_backend_role configs agent-dhcp/dns/certs/storage with generated_role_rules scoping each to its operator CRDs + pod/log reads. - Add creds policies for each role, bound to Ben's cluster-operator ldap group (human kubectl use) and the agents AppRole (programmatic use). - Add the `agents` AppRole: bind_secret_id false, token_bound_cidrs 10.10.12.200/32, deterministic role_id, 1h/4h TTLs. - Add kv/kubernetes/agents policy granting the AppRole create/read/update/list on the kubernetes KV subtree (no delete). Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT