680a0455e5
Instead of generating cluster-wide RBAC, the agent-dns role now mints tokens for a static GitOps-managed service account (argocd-apps#332) whose per-namespace RoleBindings confine access to exactly the four bind namespaces. Ordering: the argocd-apps RBAC must sync before these creds are usable, since Vault mints tokens for an SA that must already exist. - extend the kubernetes_secret_backend_role module with an optional service_account_name; when set, generated_role_rules and kubernetes_role_type are omitted (the SA's own bindings supply RBAC). - switch the agent-dns role to service_account_name agent-dns with allowed_kubernetes_namespaces bind-system; drop its generated rules. Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT