feat(binjovi): bind the application accounts to the database policies #138
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/binjovi-app-db-roles"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
First half of the OpenBao-direct database credentials change (the binjovi PR carries the workload flip and the connection-pool code). Two OpenBaoKubernetesAuthRole objects bind the binjovi and binjovi-staging application ServiceAccounts to the existing database-binjovi and database-binjovi-staging read policies (infrastructure/tenantdatabase/policy.yaml), token TTL 120s, same shape as the binjovi-forgejo-jwt role beside them.
Why: this morning the operator reconcile freeze let a rotation land in PostgreSQL without reaching the synced Secret, and staging crash-looped on invalid_password. With the pool reading static-creds from OpenBao before every connection attempt, a rotated password heals on the next attempt - no sync loop, no Secret, no restart. These roles are inert until the binjovi workload flip deploys.
https://claude.ai/code/session_01LeVatedQ4sCA1u6LHjo7B5