# One-time administrator bootstrap. CI cannot read Secrets or create workloads. apiVersion: v1 kind: ServiceAccount metadata: name: brave-sync-deployer namespace: brave-sync automountServiceAccountToken: false --- apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: brave-sync-deployer namespace: brave-sync rules: - apiGroups: [""] resources: [configmaps] resourceNames: [brave-sync-schema] verbs: [get, patch, update] - apiGroups: [""] resources: [services] resourceNames: [brave-sync, brave-sync-dynamodb, brave-sync-valkey] verbs: [get, patch, update] - apiGroups: [apps] resources: [deployments] resourceNames: [brave-sync, brave-sync-valkey] verbs: [get, patch, update, watch] - apiGroups: [apps] resources: [statefulsets] resourceNames: [brave-sync-dynamodb] verbs: [get, patch, update, watch] - apiGroups: [networking.k8s.io] resources: [ingresses] resourceNames: [brave-sync, brave-sync-compat] verbs: [get, patch, update] - apiGroups: [networking.k8s.io] resources: [networkpolicies] resourceNames: [brave-sync-backend] verbs: [get, patch, update] - apiGroups: [traefik.io] resources: [middlewares] resourceNames: [brave-sync-compat] verbs: [get, patch, update] --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: brave-sync-deployer namespace: brave-sync subjects: - kind: ServiceAccount name: brave-sync-deployer namespace: brave-sync roleRef: apiGroup: rbac.authorization.k8s.io kind: Role name: brave-sync-deployer --- apiVersion: v1 kind: Secret metadata: name: brave-sync-deployer-token namespace: brave-sync annotations: kubernetes.io/service-account.name: brave-sync-deployer type: kubernetes.io/service-account-token