This repository has been archived on 2026-04-03. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
core/k8s/rbac-traefik.yaml
Jeffrey Smith f0dd43144e rebrand: Switchboard Core → Armature
- Rename Go module switchboard-core → armature (155+ files)
- Rename Docker image → gobha/armature
- Rename K8s resources, secrets, deployments
- Rename Prometheus metrics switchboard_* → armature_*
- Rename env vars SWITCHBOARD_ADMIN_* → ARMATURE_ADMIN_*
- Rename DB names switchboard_core* → armature*
- Update all frontend branding, notification templates, docs
- Update CI scripts, e2e tests, Keycloak realm, nginx conf
- Rename scripts/switchboard-ca.sh → scripts/armature-ca.sh
- Rename k8s/switchboard.yaml → k8s/armature.yaml
- Rename chart alerting/dashboard files
- Fix: DockerHub push uses env: binding for secret injection
- Helm chart updated (name, labels, template functions, dashboard, alerting)
- Replace favicon/icon assets with Armature brand

No functional changes. Pure mechanical rename + CI fix.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-31 21:39:58 +00:00

40 lines
1.1 KiB
YAML

# k8s/rbac-traefik.yaml
# ============================================
# Grant Gitea runner SA permission to manage
# Traefik Middleware CRDs in the app namespace.
#
# Apply once per cluster/namespace:
# kubectl apply -f k8s/rbac-traefik.yaml
#
# Variables (envsubst):
# NAMESPACE - app namespace (e.g. gobha-ai-chat)
# RUNNER_SA_NS - runner SA namespace (default: gitea-runner)
# ============================================
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: traefik-middleware-manager
namespace: ${NAMESPACE}
labels:
app: armature
rules:
- apiGroups: ["traefik.io"]
resources: ["middlewares"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: gitea-runner-traefik-middleware
namespace: ${NAMESPACE}
labels:
app: armature
subjects:
- kind: ServiceAccount
name: gitea-runner-sa
namespace: ${RUNNER_SA_NS:-gitea-runner}
roleRef:
kind: Role
name: traefik-middleware-manager
apiGroup: rbac.authorization.k8s.io