From db66e50820775ff0220548f1db3c5c4cd691d00a Mon Sep 17 00:00:00 2001 From: Conan Scott Date: Wed, 14 Jan 2026 04:41:05 +0000 Subject: [PATCH] Add Vault RBAC for SCC --- templates/vault-rbac.yaml | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) create mode 100644 templates/vault-rbac.yaml diff --git a/templates/vault-rbac.yaml b/templates/vault-rbac.yaml new file mode 100644 index 0000000..842bff3 --- /dev/null +++ b/templates/vault-rbac.yaml @@ -0,0 +1,27 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: vault-restricted-scc-role +rules: +- apiGroups: + - security.openshift.io + resources: + - securitycontextconstraints + resourceNames: + - vault-restricted + verbs: + - use +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: vault-restricted-scc-binding + namespace: vault +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: vault-restricted-scc-role +subjects: +- kind: ServiceAccount + name: vault + namespace: vault