# services/hermes/chat-cluster-read-rbac.yaml # Chat's read-only window onto the cluster. The built-in `view` ClusterRole # structurally excludes Secrets everywhere, so Vault-managed material and # other credential Secrets stay invisible; the extra role adds the read-only # cluster-scoped objects `view` does not cover. No write verbs anywhere. apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: hermes-chat-cluster-view roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: view subjects: - kind: ServiceAccount name: hermes-chat namespace: hermes --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: hermes-chat-cluster-read-extra rules: - apiGroups: [""] resources: [nodes, namespaces, persistentvolumes] verbs: [get, list] - apiGroups: [storage.k8s.io] resources: [storageclasses] verbs: [get, list] - apiGroups: [apiextensions.k8s.io] resources: [customresourcedefinitions] verbs: [get, list] - apiGroups: [kustomize.toolkit.fluxcd.io, source.toolkit.fluxcd.io, helm.toolkit.fluxcd.io, image.toolkit.fluxcd.io] resources: ["*"] verbs: [get, list] - apiGroups: [metrics.k8s.io] resources: [nodes, pods] verbs: [get, list] --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: hermes-chat-cluster-read-extra roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: hermes-chat-cluster-read-extra subjects: - kind: ServiceAccount name: hermes-chat namespace: hermes