feat: prepare Eve identity retention and Binjovi access #57

Merged
binjovi-bot merged 1 commit from feat/kratos-eve-handoff into trunk 2026-09-06 03:40:37 +00:00
Owner

Prepare Eve for metadata management by Binjovi. Set Retain on the existing KratosIdentity so later source removal preserves its remote UUID and credentials. Keep the identity resource present in this release.

Allow the Binjovi control-plane pods to reach Kratos admin TCP4434. Grant its ServiceAccount GET access only to the Eve KratosIdentity so it can prove the legacy owner is absent before adoption and writes. Identity creation, passwords, and other user resources remain with their current sources.

Validation: all Ory route and new handoff source contracts passed. API-server dry-run accepts the Retain CR, network policy, and exact Role/RoleBinding. The deployed Kratos operator v0.5.23 has already passed a live disposable identity Retain proof, including deletion after password Secret removal.

Prepare Eve for metadata management by Binjovi. Set Retain on the existing KratosIdentity so later source removal preserves its remote UUID and credentials. Keep the identity resource present in this release. Allow the Binjovi control-plane pods to reach Kratos admin TCP4434. Grant its ServiceAccount GET access only to the Eve KratosIdentity so it can prove the legacy owner is absent before adoption and writes. Identity creation, passwords, and other user resources remain with their current sources. Validation: all Ory route and new handoff source contracts passed. API-server dry-run accepts the Retain CR, network policy, and exact Role/RoleBinding. The deployed Kratos operator v0.5.23 has already passed a live disposable identity Retain proof, including deletion after password Secret removal.
feat: prepare Eve identity retention and Binjovi access
All checks were successful
binjovi/ci Binjovi completed the frozen plan
87a0e057dd
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
sean/ory!57
No description provided.