deploy: scope state access for Longhorn backups

This commit is contained in:
codex 2026-10-03 16:00:22 -05:00
parent f167d7d17d
commit 3c0c868708
5 changed files with 57 additions and 10 deletions

View File

@ -1,6 +0,0 @@
misconfigurations:
- id: KSV-0041
paths:
- deploy/clusterrole.yaml
expired_at: 2026-05-22
statement: Soteria copies restic credentials into target namespaces for backup Jobs; replace with a narrower per-namespace secret distribution model.

16
deploy/NOTES.md Normal file
View File

@ -0,0 +1,16 @@
# Default deployment permissions
This deployment uses the Longhorn backend. It reads inventory across namespaces
and updates only `soteria-policies` and `soteria-backup-usage` in its own namespace.
The empty Secret declarations create those records on first deployment; they
deliberately contain no data field, so application-written state is preserved.
The optional `soteria-restic` credential is readable by exact name only.
Changing the state or credential names also requires updating the Role. Do not
restore cluster-wide Secret access to accommodate another deployment.
The optional restic backend needs additional, explicitly approved Roles and
RoleBindings in each backup/restore target namespace: Job creation and the
credential-copy operations in `internal/k8s/jobs.go`. Those grants are not part
of this Longhorn deployment. Review credential distribution before enabling
restic; Kubernetes RBAC cannot restrict Secret creation by resource name.

View File

@ -8,9 +8,6 @@ rules:
- apiGroups: [""]
resources: ["persistentvolumeclaims", "persistentvolumes"]
verbs: ["get", "list"]
- apiGroups: [""]
resources: ["secrets"]
verbs: ["get", "list", "create", "update", "delete"]
- apiGroups: ["batch"]
resources: ["jobs"]
verbs: ["get", "list", "create"]
verbs: ["get", "list"]

View File

@ -7,5 +7,6 @@ resources:
- serviceaccount.yaml
- clusterrole.yaml
- clusterrolebinding.yaml
- state-access.yaml
- deployment.yaml
- service.yaml

39
deploy/state-access.yaml Normal file
View File

@ -0,0 +1,39 @@
# The default Longhorn mode writes only its own policy and usage records.
apiVersion: v1
kind: Secret
metadata:
name: soteria-policies
type: Opaque
---
apiVersion: v1
kind: Secret
metadata:
name: soteria-backup-usage
type: Opaque
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: soteria-state
rules:
- apiGroups: [""]
resources: ["secrets"]
resourceNames: ["soteria-policies", "soteria-backup-usage"]
verbs: ["get", "update"]
- apiGroups: [""]
resources: ["secrets"]
resourceNames: ["soteria-restic"]
verbs: ["get"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: soteria-state
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: soteria-state
subjects:
- kind: ServiceAccount
name: soteria
namespace: soteria