Skip to content

Tbt/auth daemon config secret#1333

Open
TBThomas56 wants to merge 4 commits into
mainfrom
tbt/auth-daemon-config-secret
Open

Tbt/auth daemon config secret#1333
TBThomas56 wants to merge 4 commits into
mainfrom
tbt/auth-daemon-config-secret

Conversation

@TBThomas56
Copy link
Copy Markdown
Contributor

Distributes auth-daemon-config secret to session namespaces from workflows namespace (GeneratingPolicy) and enforces access controls to protect sensitive content

Cronjob acts as fallback for existing namespaces and secret rotation.

Kyverno clusterpolicy enforces that only containers running the auth-daemon image may mount or reference the secret and blocks any exec into any pod that runs auth-daemon.
PS: I believe pods running alongside it can access it

@TBThomas56 TBThomas56 force-pushed the tbt/auth-daemon-config-secret branch from a87080a to 1125443 Compare May 22, 2026 12:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant