c0cc74927c
ci/woodpecker/push/apply Pipeline was successful
## Why logarchiver encrypts archived logs to an OpenPGP key held in Vault's gpg engine so the private key never leaves Vault (retrieval delegates decryption to `gpg/decrypt/logarchive`, operator-only). This provisions the key and lets the service read only its public key. ## Changes - Create gpg key `logarchive` (rsa-4096, non-exportable) in the `gpg` mount. - Add k8s auth role `logging_logarchiver` bound to SA `logarchiver` in the `logging` namespace. - Add policy granting `read` on `gpg/keys/logarchive` to that role (public key only; no decrypt/export). Cross-repo: this must apply before the argocd-apps logarchiver Deployment (unkin/argocd-apps) can fetch the key. https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv --------- Co-authored-by: benvin <neotheo@gmail.com> Reviewed-on: #106 Co-authored-by: Ben Vincent <ben@unkin.net> Co-committed-by: Ben Vincent <ben@unkin.net>
13 lines
368 B
YAML
13 lines
368 B
YAML
# Allow the logarchiver service (logging namespace, SA logarchiver) to read the
|
|
# logarchive public key. A plain read on gpg/keys/logarchive returns the armored
|
|
# public_key; no decrypt/export capability is granted (decrypt stays operator-only).
|
|
---
|
|
rules:
|
|
- path: "gpg/keys/logarchive"
|
|
capabilities:
|
|
- read
|
|
|
|
auth:
|
|
k8s/au/syd1:
|
|
- logging_logarchiver
|