vault's terraform approle doesnt need to access all of these kubernetes roles, it was just added as a placeholder and access to the kubernetes roles was via the `vault_admin` to-much-access account. this is an effort to roll back that and make access more targeted. - add kubernetes* ldap groups for specific cluster/role combinations - remove tf_vault from kubernetes* roles |
||
|---|---|---|
| .. | ||
| cluster-admin.yaml | ||
| cluster-operator.yaml | ||
| cluster-root.yaml | ||
| media-apps-operator.yaml | ||