fix(ci): authorize sealed database reconciliation
All checks were successful
CI and deploy / verify (push) Successful in 2m10s
CI and deploy / publish (push) Successful in 37s
CI and deploy / deploy (push) Successful in 2m7s
CI and deploy / mirror (push) Has been skipped

This commit is contained in:
Alex 2026-08-28 01:15:32 +02:00
parent 12ac14f709
commit 538dee3cce
3 changed files with 40 additions and 0 deletions

View file

@ -0,0 +1,7 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: nereus
resources:
- nereus-deployer-sealedsecrets.yaml

View file

@ -0,0 +1,22 @@
# Bootstrap once with cluster-admin. The deployer cannot grant itself access.
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: nereus-deployer-sealedsecrets
rules:
- apiGroups: ["bitnami.com"]
resources: ["sealedsecrets"]
verbs: ["get", "list", "watch", "create", "update", "patch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: nereus-deployer-sealedsecrets
subjects:
- kind: ServiceAccount
name: nereus-deployer
namespace: kube-system
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: nereus-deployer-sealedsecrets

View file

@ -28,6 +28,17 @@ After registering that deploy key, set the Forgejo Actions repository variable
`MIRROR_ENABLED` to `true`. The mirror job stays skipped until both sides `MIRROR_ENABLED` to `true`. The mirror job stays skipped until both sides
are configured, so an absent GitHub credential cannot break production deploys. are configured, so an absent GitHub credential cannot break production deploys.
Before the first sealed deployment, a cluster administrator must bootstrap the
deployer's namespaced SealedSecret permission:
```bash
kubectl apply -k deploy/rbac
```
The deployer cannot grant this Role to itself. The Role permits only management
and waiting on `bitnami.com/sealedsecrets` in `nereus`; the controller remains
the only identity allowed to create the decrypted Secret.
The workflow never prints these values. It writes the kubeconfig to the The workflow never prints these values. It writes the kubeconfig to the
ephemeral workspace with mode `0600`, removes it in an `always()` step, and ephemeral workspace with mode `0600`, removes it in an `always()` step, and
creates the Kubernetes registry pull secret through a pipe so its generated creates the Kubernetes registry pull secret through a pipe so its generated