Files
terraform-vault/resources
unkinben 680a0455e5
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
Rework agent-dns to service_account_name mode against a static SA
Instead of generating cluster-wide RBAC, the agent-dns role now mints
tokens for a static GitOps-managed service account (argocd-apps#332)
whose per-namespace RoleBindings confine access to exactly the four bind
namespaces. Ordering: the argocd-apps RBAC must sync before these creds
are usable, since Vault mints tokens for an SA that must already exist.

- extend the kubernetes_secret_backend_role module with an optional
  service_account_name; when set, generated_role_rules and
  kubernetes_role_type are omitted (the SA's own bindings supply RBAC).
- switch the agent-dns role to service_account_name agent-dns with
  allowed_kubernetes_namespaces bind-system; drop its generated rules.

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
2026-08-02 21:45:26 +10:00
..