# Least-privilege RBAC for the adguard TLS cert sync CronJob (see cert-sync.yaml). # # The job runs as ServiceAccount `adguard-cert-sync` (namespace adguard) and needs: # * namespace traefik: list/get pods (locate the running Traefik pod by label) # and create pods/exec (read-only `cat` of /data/letsencrypt/acme.json). # It never writes anything in namespace traefik. # * namespace adguard: get/update/patch Secret `adguard-certs` (the only # secret it may touch) and get/list/watch/patch Deployment # `adguard-deployment` (`rollout restart` issues a patch, # `rollout status` needs list+watch). apiVersion: v1 kind: ServiceAccount metadata: name: adguard-cert-sync namespace: adguard labels: app: adguard --- apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: adguard-cert-sync namespace: adguard labels: app: adguard rules: - apiGroups: [""] resources: ["secrets"] resourceNames: ["adguard-certs"] verbs: ["get", "update", "patch"] - apiGroups: ["apps"] resources: ["deployments"] resourceNames: ["adguard-deployment"] verbs: ["get", "patch"] # NOTE: list/watch cannot be combined with resourceNames (the API ignores # the name filter for collection verbs, so the grant would be void). # This rule is namespace-scoped to adguard, which holds a single # Deployment; `rollout status` needs it to watch the rollout. - apiGroups: ["apps"] resources: ["deployments"] verbs: ["list", "watch"] --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: adguard-cert-sync namespace: adguard labels: app: adguard subjects: - kind: ServiceAccount name: adguard-cert-sync namespace: adguard roleRef: kind: Role name: adguard-cert-sync apiGroup: rbac.authorization.k8s.io --- # Read-only access to the Traefik pod (acme.json lives on its /data volume). # The RoleBinding references a ServiceAccount from namespace adguard, # which is allowed: the binding lives in namespace traefik and only # grants rights inside namespace traefik. apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: adguard-cert-sync namespace: traefik labels: app: adguard rules: - apiGroups: [""] resources: ["pods"] verbs: ["get", "list"] - apiGroups: [""] resources: ["pods/exec"] verbs: ["create"] --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: adguard-cert-sync namespace: traefik labels: app: adguard subjects: - kind: ServiceAccount name: adguard-cert-sync namespace: adguard roleRef: kind: Role name: adguard-cert-sync apiGroup: rbac.authorization.k8s.io