Files
homelab/adguardhome/k8s/cert-sync-rbac.yaml
T
forust 93d768e988
ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 5s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 2s
ci / build (push) Skipped
ci / deploy-userbot-panel (push) Skipped
fix(adguard): split deployment RBAC rule for list/watch
Collection verbs cannot combine with resourceNames (grant would
be void). Instance verbs stay name-scoped to adguard-deployment;
list/watch is namespace-scoped (single Deployment in ns).
2026-09-23 13:54:06 +02:00

93 lines
2.6 KiB
YAML

# Least-privilege RBAC for the adguard TLS cert sync CronJob (see cert-sync.yaml).
#
# The job runs as ServiceAccount `adguard-cert-sync` (namespace adguard) and needs:
# * namespace traefik: list/get pods (locate the running Traefik pod by label)
# and create pods/exec (read-only `cat` of /data/letsencrypt/acme.json).
# It never writes anything in namespace traefik.
# * namespace adguard: get/update/patch Secret `adguard-certs` (the only
# secret it may touch) and get/list/watch/patch Deployment
# `adguard-deployment` (`rollout restart` issues a patch,
# `rollout status` needs list+watch).
apiVersion: v1
kind: ServiceAccount
metadata:
name: adguard-cert-sync
namespace: adguard
labels:
app: adguard
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: adguard-cert-sync
namespace: adguard
labels:
app: adguard
rules:
- apiGroups: [""]
resources: ["secrets"]
resourceNames: ["adguard-certs"]
verbs: ["get", "update", "patch"]
- apiGroups: ["apps"]
resources: ["deployments"]
resourceNames: ["adguard-deployment"]
verbs: ["get", "patch"]
# NOTE: list/watch cannot be combined with resourceNames (the API ignores
# the name filter for collection verbs, so the grant would be void).
# This rule is namespace-scoped to adguard, which holds a single
# Deployment; `rollout status` needs it to watch the rollout.
- apiGroups: ["apps"]
resources: ["deployments"]
verbs: ["list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: adguard-cert-sync
namespace: adguard
labels:
app: adguard
subjects:
- kind: ServiceAccount
name: adguard-cert-sync
namespace: adguard
roleRef:
kind: Role
name: adguard-cert-sync
apiGroup: rbac.authorization.k8s.io
---
# Read-only access to the Traefik pod (acme.json lives on its /data volume).
# The RoleBinding references a ServiceAccount from namespace adguard,
# which is allowed: the binding lives in namespace traefik and only
# grants rights inside namespace traefik.
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: adguard-cert-sync
namespace: traefik
labels:
app: adguard
rules:
- apiGroups: [""]
resources: ["pods"]
verbs: ["get", "list"]
- apiGroups: [""]
resources: ["pods/exec"]
verbs: ["create"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: adguard-cert-sync
namespace: traefik
labels:
app: adguard
subjects:
- kind: ServiceAccount
name: adguard-cert-sync
namespace: adguard
roleRef:
kind: Role
name: adguard-cert-sync
apiGroup: rbac.authorization.k8s.io