Skip to content

Tbt/auth daemon config secret#1333

Open
TBThomas56 wants to merge 7 commits into
mainfrom
tbt/auth-daemon-config-secret
Open

Tbt/auth daemon config secret#1333
TBThomas56 wants to merge 7 commits into
mainfrom
tbt/auth-daemon-config-secret

Conversation

@TBThomas56
Copy link
Copy Markdown
Contributor

Distributes auth-daemon-config secret to session namespaces from workflows namespace (GeneratingPolicy) and enforces access controls to protect sensitive content

Cronjob acts as fallback for existing namespaces and secret rotation.

Kyverno clusterpolicy enforces that only containers running the auth-daemon image may mount or reference the secret and blocks any exec into any pod that runs auth-daemon.
PS: I believe pods running alongside it can access it

Copy link
Copy Markdown
Collaborator

@davehadley davehadley left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yikes! More state being synced to visit namespaces. 😭

@TBThomas56 TBThomas56 force-pushed the tbt/auth-daemon-config-secret branch 5 times, most recently from b7f05ca to 875ef4b Compare May 26, 2026 15:03
@TBThomas56 TBThomas56 force-pushed the tbt/auth-daemon-config-secret branch from ea81f01 to 5d748ad Compare May 27, 2026 12:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants