soteria/deploy/NOTES.md

960 B

Default deployment permissions

This deployment uses the Longhorn backend. It reads inventory across namespaces and updates only soteria-policies and soteria-backup-usage in its own namespace. The empty Secret declarations create those records on first deployment; they deliberately contain no data field, so application-written state is preserved. The optional soteria-restic credential is readable by exact name only.

Changing the state or credential names also requires updating the Role. Do not restore cluster-wide Secret access to accommodate another deployment.

The optional restic backend needs additional, explicitly approved Roles and RoleBindings in each backup/restore target namespace: Job creation and the credential-copy operations in internal/k8s/jobs.go. Those grants are not part of this Longhorn deployment. Review credential distribution before enabling restic; Kubernetes RBAC cannot restrict Secret creation by resource name.