Establish clean homelab infrastructure baseline
Reorganize the brownfield repository, remove retired and generated artifacts, harden ignore rules, and record the GitOps/IaC redesign.
This commit is contained in:
@@ -0,0 +1,6 @@
|
||||
# Ansible managed
|
||||
# Broad admin for human OIDC logins (mapped from the vault-admins AD group).
|
||||
# Homelab-broad on purpose; scope down to specific mounts if you want least privilege.
|
||||
path "*" {
|
||||
capabilities = ["create", "read", "update", "delete", "list", "sudo"]
|
||||
}
|
||||
@@ -0,0 +1,5 @@
|
||||
# Ansible managed
|
||||
# The AI agent may sign short-lived SSH client certs for the ai-agent role — nothing else.
|
||||
path "ssh-client-signer/sign/ai-agent" {
|
||||
capabilities = ["create", "update"]
|
||||
}
|
||||
@@ -0,0 +1,17 @@
|
||||
# Read-only access for the External Secrets Operator in k3s.
|
||||
#
|
||||
# Scoped to kv/k8s/* deliberately — ESO syncs Kubernetes Secrets and has no reason
|
||||
# to see the SSH CA, the PKI, or any other KV path. This is narrower than the human
|
||||
# `admin` policy, which is the point: the machine identity is less privileged than
|
||||
# the person.
|
||||
#
|
||||
# KV v2 splits data from metadata: reads go to <mount>/data/<path>, and listing or
|
||||
# checking existence goes to <mount>/metadata/<path>. ESO needs both — without
|
||||
# metadata it cannot resolve `dataFrom.extract`.
|
||||
path "kv/data/k8s/*" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
|
||||
path "kv/metadata/k8s/*" {
|
||||
capabilities = ["read", "list"]
|
||||
}
|
||||
@@ -0,0 +1,5 @@
|
||||
# Ansible managed
|
||||
# Read-only access to take Raft snapshots — used by the snapshot timer's token.
|
||||
path "sys/storage/raft/snapshot" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
Reference in New Issue
Block a user