fix(security): constrain auth endpoints and certificate issuance #96

Merged
sean merged 1 commit from fix/secure-openbao-addresses into trunk 2026-08-06 10:26:33 +00:00
Owner

Reject CR-driven OpenBao JWT redirection by default, reduce TokenRequest RBAC to create-only, and revoke unpublished PKI leaves when Secret writes fail. Includes red/green security tests and regenerated RBAC.

Reject CR-driven OpenBao JWT redirection by default, reduce TokenRequest RBAC to create-only, and revoke unpublished PKI leaves when Secret writes fail. Includes red/green security tests and regenerated RBAC.
fix(security): constrain auth endpoints and certificate issuance
All checks were successful
pipeline/ci CI green @ 36a0863d427e
36a0863d42
sean merged commit 36a0863d42 into trunk 2026-08-06 10:26:33 +00:00
sean deleted branch fix/secure-openbao-addresses 2026-08-06 10:26:33 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
sean/openbao-operator!96
No description provided.