Skip to content

Security

Layers, each consuming the one before it: OpenBao is the cluster’s secrets and PKI backend; Secrets covers where a credential lives, who may read and write it, and what a developer writes to give an application one of its own; PKI & Secrets covers the certificate half — how cert-manager issues from the PKI — and the bootstrap tier that stays in the cloud’s managed store; Policies covers what’s enforced once a workload is running — Kyverno admission, CiliumNetworkPolicy default-deny, and pod security context.

The repository’s security policy covers reporting, the enforced posture in summary, and the limitations this platform accepts as a reference implementation — including the ones it would be more comfortable not to mention.

These pages describe how the platform implements security. The rules themselves — required security-context fields, RBAC conventions, IAM scoping — are the Platform Constitution; this section links to it rather than restating it.

Two secret paths sharing one private CA: an offline root CA signs each cloud’s intermediate once with openssl, outside OpenBao, and only the intermediate’s certificate and key are imported into the pki_private_issuer mount, which is then the issuer that signs every leaf certificate cert-manager requests through the openbao ClusterIssuer; alongside it, External Secrets Operator authenticates to the cloud’s managed secret store (AWS Secrets Manager / GCP Secret Manager) through a ClusterSecretStore and materialises every other credential as a Kubernetes Secret