diff --git a/.trivyignore.yaml b/.trivyignore.yaml deleted file mode 100644 index ef10790..0000000 --- a/.trivyignore.yaml +++ /dev/null @@ -1,6 +0,0 @@ -misconfigurations: - - id: KSV-0041 - paths: - - deploy/clusterrole.yaml - expired_at: 2026-05-22 - statement: Soteria copies restic credentials into target namespaces for backup Jobs; replace with a narrower per-namespace secret distribution model. diff --git a/deploy/NOTES.md b/deploy/NOTES.md new file mode 100644 index 0000000..7ab35f2 --- /dev/null +++ b/deploy/NOTES.md @@ -0,0 +1,16 @@ +# Default deployment permissions + +This deployment uses the Longhorn backend. It reads inventory across namespaces +and updates only `soteria-policies` and `soteria-backup-usage` in its own namespace. +The empty Secret declarations create those records on first deployment; they +deliberately contain no data field, so application-written state is preserved. +The optional `soteria-restic` credential is readable by exact name only. + +Changing the state or credential names also requires updating the Role. Do not +restore cluster-wide Secret access to accommodate another deployment. + +The optional restic backend needs additional, explicitly approved Roles and +RoleBindings in each backup/restore target namespace: Job creation and the +credential-copy operations in `internal/k8s/jobs.go`. Those grants are not part +of this Longhorn deployment. Review credential distribution before enabling +restic; Kubernetes RBAC cannot restrict Secret creation by resource name. diff --git a/deploy/clusterrole.yaml b/deploy/clusterrole.yaml index ec2f883..081f5b8 100644 --- a/deploy/clusterrole.yaml +++ b/deploy/clusterrole.yaml @@ -8,9 +8,6 @@ rules: - apiGroups: [""] resources: ["persistentvolumeclaims", "persistentvolumes"] verbs: ["get", "list"] - - apiGroups: [""] - resources: ["secrets"] - verbs: ["get", "list", "create", "update", "delete"] - apiGroups: ["batch"] resources: ["jobs"] - verbs: ["get", "list", "create"] + verbs: ["get", "list"] diff --git a/deploy/kustomization.yaml b/deploy/kustomization.yaml index 2dc9c38..4d09c5c 100644 --- a/deploy/kustomization.yaml +++ b/deploy/kustomization.yaml @@ -7,5 +7,6 @@ resources: - serviceaccount.yaml - clusterrole.yaml - clusterrolebinding.yaml + - state-access.yaml - deployment.yaml - service.yaml diff --git a/deploy/state-access.yaml b/deploy/state-access.yaml new file mode 100644 index 0000000..9c74ae4 --- /dev/null +++ b/deploy/state-access.yaml @@ -0,0 +1,39 @@ +# The default Longhorn mode writes only its own policy and usage records. +apiVersion: v1 +kind: Secret +metadata: + name: soteria-policies +type: Opaque +--- +apiVersion: v1 +kind: Secret +metadata: + name: soteria-backup-usage +type: Opaque +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: soteria-state +rules: + - apiGroups: [""] + resources: ["secrets"] + resourceNames: ["soteria-policies", "soteria-backup-usage"] + verbs: ["get", "update"] + - apiGroups: [""] + resources: ["secrets"] + resourceNames: ["soteria-restic"] + verbs: ["get"] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: soteria-state +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: soteria-state +subjects: + - kind: ServiceAccount + name: soteria + namespace: soteria