Logo
Explore Help
Sign In
titan/atlas-iac
3
0
Fork 0
You've already forked atlas-iac
Code Issues Pull Requests 9 Actions Packages Projects Releases Wiki Activity
atlas-iac/services/hermes/plugins/cluster-read/plugin.yaml

5 lines
139 B
YAML
Raw Normal View History

hermes(chat): read-only Atlas cluster visibility for chat RBAC: the built-in view ClusterRole (which never includes Secrets, so Vault-managed material stays structurally invisible) plus a read-only extra for nodes, namespaces, PVs, storage classes, CRDs, Flux resources and metrics, bound to the chat service account. Tooling: a cluster-read plugin registers a GET-only cluster_read tool against the in-cluster API using the pod's projected token - secrets paths refused in the handler as well, malformed segments rejected, responses bounded and stripped of managedFields noise. Classified read_files/low in the HUX capability map. RBAC applies on push; the tool activates when the pods next roll (bundled with the round-3 voice build). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BvMSXH8VH2tMWXanb8SJdf
2026-08-24 13:33:48 -03:00
name: cluster-read
version: "1"
description: Read-only Atlas cluster visibility for chat; Secrets are structurally excluded.
kind: backend
Reference in New Issue Copy Permalink
Powered by Gitea Version: 1.23.8 Page: 809ms Template: 3ms
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API