deploy: scope state access for Longhorn backups
This commit is contained in:
parent
f167d7d17d
commit
3c0c868708
@ -1,6 +0,0 @@
|
||||
misconfigurations:
|
||||
- id: KSV-0041
|
||||
paths:
|
||||
- deploy/clusterrole.yaml
|
||||
expired_at: 2026-05-22
|
||||
statement: Soteria copies restic credentials into target namespaces for backup Jobs; replace with a narrower per-namespace secret distribution model.
|
||||
16
deploy/NOTES.md
Normal file
16
deploy/NOTES.md
Normal file
@ -0,0 +1,16 @@
|
||||
# Default deployment permissions
|
||||
|
||||
This deployment uses the Longhorn backend. It reads inventory across namespaces
|
||||
and updates only `soteria-policies` and `soteria-backup-usage` in its own namespace.
|
||||
The empty Secret declarations create those records on first deployment; they
|
||||
deliberately contain no data field, so application-written state is preserved.
|
||||
The optional `soteria-restic` credential is readable by exact name only.
|
||||
|
||||
Changing the state or credential names also requires updating the Role. Do not
|
||||
restore cluster-wide Secret access to accommodate another deployment.
|
||||
|
||||
The optional restic backend needs additional, explicitly approved Roles and
|
||||
RoleBindings in each backup/restore target namespace: Job creation and the
|
||||
credential-copy operations in `internal/k8s/jobs.go`. Those grants are not part
|
||||
of this Longhorn deployment. Review credential distribution before enabling
|
||||
restic; Kubernetes RBAC cannot restrict Secret creation by resource name.
|
||||
@ -8,9 +8,6 @@ rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["persistentvolumeclaims", "persistentvolumes"]
|
||||
verbs: ["get", "list"]
|
||||
- apiGroups: [""]
|
||||
resources: ["secrets"]
|
||||
verbs: ["get", "list", "create", "update", "delete"]
|
||||
- apiGroups: ["batch"]
|
||||
resources: ["jobs"]
|
||||
verbs: ["get", "list", "create"]
|
||||
verbs: ["get", "list"]
|
||||
|
||||
@ -7,5 +7,6 @@ resources:
|
||||
- serviceaccount.yaml
|
||||
- clusterrole.yaml
|
||||
- clusterrolebinding.yaml
|
||||
- state-access.yaml
|
||||
- deployment.yaml
|
||||
- service.yaml
|
||||
|
||||
39
deploy/state-access.yaml
Normal file
39
deploy/state-access.yaml
Normal file
@ -0,0 +1,39 @@
|
||||
# The default Longhorn mode writes only its own policy and usage records.
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: soteria-policies
|
||||
type: Opaque
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: soteria-backup-usage
|
||||
type: Opaque
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: soteria-state
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["secrets"]
|
||||
resourceNames: ["soteria-policies", "soteria-backup-usage"]
|
||||
verbs: ["get", "update"]
|
||||
- apiGroups: [""]
|
||||
resources: ["secrets"]
|
||||
resourceNames: ["soteria-restic"]
|
||||
verbs: ["get"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: soteria-state
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: soteria-state
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: soteria
|
||||
namespace: soteria
|
||||
Loading…
x
Reference in New Issue
Block a user