Skip to content

Which mount, and why not secret

This root owns its own seaweedfs kv-v2 mount. terraform/40_openbao-config owns secret; two roots declaring the same vault_mount is a state fight, and a dedicated mount makes the policy paths (seaweedfs/data/<namespace>/<bucket>) fall out without prefix gymnastics.

Layout under the mount:

Object Name
Mount seaweedfs (kv-v2)
KV entry <namespace>/<bucket>, e.g. observability/loki
Policy seaweedfs-<namespace>-<bucket>, e.g. seaweedfs-observability-loki
Kubernetes auth role seaweedfs-<namespace>, e.g. seaweedfs-observability

Each policy grants read on seaweedfs/data/<ns>/<bucket> and seaweedfs/metadata/<ns>/<bucket> and nothing else. The role carries every policy for its namespace, so a pod in observability can read all three observability entries and no entry belonging to another namespace.

The Kubernetes auth backend itself is not declared here. The OpenBao Helm release bootstraps auth/kubernetes, the admin policy and the admin role through its initialize stanza; this root only adds roles underneath it. So flux/30_openbao must be reconciled before the first apply.