Automate tenant-scoped service accounts & kubeconfigs #46

Open
opened 2025-09-01 14:20:02 +00:00 by chris · 0 comments
Owner

Description

  • Provide a script or controller that creates a namespace, a serviceaccount limited to that namespace, and generates a short-lived kubeconfig token for runner jobs.

Priority: P0
Estimate: 6 hours
Acceptance criteria

  • A generated kubeconfig can only perform operations inside the tenant namespace.
  • Attempts to access other namespaces fail.
Description - Provide a script or controller that creates a namespace, a serviceaccount limited to that namespace, and generates a short-lived kubeconfig token for runner jobs. Priority: P0 Estimate: 6 hours Acceptance criteria - A generated kubeconfig can only perform operations inside the tenant namespace. - Attempts to access other namespaces fail.
chris added this to the C - IaC Flow for Customers milestone 2025-09-01 14:20:02 +00:00
chris added the
security
automation
k8s
labels 2025-09-01 14:20:02 +00:00
chris self-assigned this 2025-09-01 14:20:02 +00:00
chris added this to the MVP project 2025-09-03 06:51:58 +00:00
This repository is archived. You cannot comment on issues.
No description provided.