Skip to content

chore: service account migration - #562

Merged
JasonPowr merged 1 commit into
mainfrom
sa-migration
Jul 24, 2026
Merged

chore: service account migration#562
JasonPowr merged 1 commit into
mainfrom
sa-migration

Conversation

@JasonPowr

Copy link
Copy Markdown
Member

No description provided.

@github-actions

Copy link
Copy Markdown

Configuration Diff

35 document(s) impacted:

+ 2 added
- 5 removed
! 28 modified
Diff
@@ spec.tenantPipeline.serviceAccountName @@
# appstudio.redhat.com/v1alpha1/ReleasePlan/rhtas-tenant/deploy-konflux-configuration-as-code
! ± value change
- konflux-configuration-as-code-deployer
+ konflux-bot-1

@@ spec.resources.appstudio.redhat.com/v1alpha1/ReleasePlan/promote-to-candidate-{{.application}}{{.nameSuffix}}.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/ansible-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.ReleasePlan.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/client-server-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.ReleasePlan.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/create-tree-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.ReleasePlan.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/model-transparency-go-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.ReleasePlan.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/model-transparency-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.appstudio.redhat.com/v1alpha1/ReleasePlan/promote-to-candidate-{{.application}}{{.nameSuffix}}.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/mvo-fbc-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.appstudio.redhat.com/v1alpha1/ReleasePlan/promote-to-candidate-{{.application}}{{.nameSuffix}}.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/operator-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.appstudio.redhat.com/v1alpha1/ReleasePlan/promote-to-candidate-{{.application}}{{.nameSuffix}}.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/pco-fbc-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.appstudio.redhat.com/v1alpha1/ReleasePlan/promote-to-candidate-{{.application}}{{.nameSuffix}}.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/policy-controller-operator-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.ReleasePlan.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/policy-controller-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.appstudio.redhat.com/v1alpha1/ReleasePlan/promote-to-candidate-{{.application}}{{.nameSuffix}}.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/rekor-monitor-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.appstudio.redhat.com/v1alpha1/ReleasePlan/promote-to-candidate-{{.application}}{{.nameSuffix}}.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/rhtas-console-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.appstudio.redhat.com/v1alpha1/ReleasePlan/promote-to-candidate-{{.application}}{{.nameSuffix}}.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/rhtas-fbc-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.ReleasePlan.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/segment-backup-job-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.ReleasePlan.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/sigstore-a2a-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.appstudio.redhat.com/v1alpha1/ReleasePlan/promote-to-candidate-{{.application}}{{.nameSuffix}}.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/tas-components-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.appstudio.redhat.com/v1alpha1/ReleasePlan/promote-to-candidate-{{.application}}{{.nameSuffix}}.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/tas-tools-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.appstudio.redhat.com/v1alpha1/ReleasePlan/promote-to-candidate-{{.application}}{{.nameSuffix}}.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/tough-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ spec.resources.appstudio.redhat.com/v1alpha1/ReleasePlan/promote-to-candidate-{{.application}}{{.nameSuffix}}.spec.tenantPipeline.serviceAccountName @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/tufcli-template
! ± value change
- rhtas-build-bot
+ konflux-bot-0

@@ metadata.name @@
# rbac.authorization.k8s.io/v1/Role/rhtas-tenant/konflux-bot-1-role
! ± value change
- konflux-configuration-as-code-role
+ konflux-bot-1-role

@@ metadata.name @@
# rbac.authorization.k8s.io/v1/Role/rhtas-tenant/konflux-bot-0-role
! ± value change
- rhtas-build-bot-role
+ konflux-bot-0-role

@@ metadata.name @@
# rbac.authorization.k8s.io/v1/RoleBinding/rhtas-tenant/konflux-bot-1-rolebinding
! ± value change
- rhtas-release-rolebinding
+ konflux-bot-1-rolebinding

@@ roleRef.name @@
# rbac.authorization.k8s.io/v1/RoleBinding/rhtas-tenant/konflux-bot-1-rolebinding
! ± value change
- rhtas-release-role
+ konflux-bot-1-role

@@ subjects @@
# rbac.authorization.k8s.io/v1/RoleBinding/rhtas-tenant/konflux-bot-1-rolebinding
! - one list entry removed:
- - name: rhtas-release
-   kind: ServiceAccount
-   namespace: rhtas-tenant
! + one list entry added:
+   - name: konflux-bot-1
+     kind: ServiceAccount
+     namespace: rhtas-tenant

@@ metadata.name @@
# rbac.authorization.k8s.io/v1/RoleBinding/rhtas-tenant/konflux-bot-0-rolebinding
! ± value change
- rhtas-build-bot-rolebinding
+ konflux-bot-0-rolebinding

@@ roleRef.name @@
# rbac.authorization.k8s.io/v1/RoleBinding/rhtas-tenant/konflux-bot-0-rolebinding
! ± value change
- rhtas-build-bot-role
+ konflux-bot-0-role

@@ subjects @@
# rbac.authorization.k8s.io/v1/RoleBinding/rhtas-tenant/konflux-bot-0-rolebinding
! - one list entry removed:
- - name: rhtas-build-bot
-   kind: ServiceAccount
-   namespace: rhtas-tenant
! + one list entry added:
+   - name: konflux-bot-0
+     kind: ServiceAccount
+     namespace: rhtas-tenant

@@ (root level) @@
# v1/ServiceAccount/rhtas-tenant/konflux-configuration-as-code-deployer
! - one document removed:
- ---
- apiVersion: v1
- kind: ServiceAccount
- metadata:
-   name: konflux-configuration-as-code-deployer
-   namespace: rhtas-tenant

@@ (root level) @@
# v1/ServiceAccount/rhtas-tenant/rhtas-build-bot
! - one document removed:
- ---
- apiVersion: v1
- kind: ServiceAccount
- metadata:
-   name: rhtas-build-bot
-   namespace: rhtas-tenant

@@ (root level) @@
# v1/ServiceAccount/rhtas-tenant/rhtas-release
! - one document removed:
- ---
- apiVersion: v1
- kind: ServiceAccount
- metadata:
-   name: rhtas-release
-   namespace: rhtas-tenant

@@ (root level) @@
# rbac.authorization.k8s.io/v1/Role/rhtas-tenant/rhtas-release-role
! - one document removed:
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: Role
- metadata:
-   name: rhtas-release-role
-   namespace: rhtas-tenant
- rules:
- - resources:
-   - releaseplans
-   - releases
-   apiGroups:
-   - appstudio.redhat.com
-   verbs:
-   - get
-   - list
-   - watch
-   - create
-   - update
-   - patch
-   - delete

@@ (root level) @@
# rbac.authorization.k8s.io/v1/RoleBinding/rhtas-tenant/konflux-configuration-as-code-deployer-rolebinding
! - one document removed:
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: RoleBinding
- metadata:
-   name: konflux-configuration-as-code-deployer-rolebinding
-   namespace: rhtas-tenant
- roleRef:
-   name: konflux-configuration-as-code-role
-   apiGroup: rbac.authorization.k8s.io
-   kind: Role
- subjects:
- - name: konflux-configuration-as-code-deployer
-   kind: ServiceAccount
-   namespace: rhtas-tenant

@@ (root level) @@
# v1/ServiceAccount/rhtas-tenant/konflux-bot-0
! + one document added:
+   ---
+   apiVersion: v1
+   imagePullSecrets:
+   - name: registry-redhat-io-pull-secret
+   kind: ServiceAccount
+   metadata:
+     name: konflux-bot-0
+     namespace: rhtas-tenant
+     labels:
+       rhtas.redhat.com/sa-group: build-ci-release

@@ (root level) @@
# v1/ServiceAccount/rhtas-tenant/konflux-bot-1
! + one document added:
+   ---
+   apiVersion: v1
+   kind: ServiceAccount
+   metadata:
+     name: konflux-bot-1
+     namespace: rhtas-tenant
+     labels:
+       rhtas.redhat.com/sa-group: konflux-configuration-as-code-deployer

📦 Artifacts: base-output.yaml, head-output.yaml, dyff-output.txt

@qodo-for-securesign

Copy link
Copy Markdown

PR Summary by Qodo

Migrate Konflux configs to konflux-bot service accounts

⚙️ Configuration changes 📝 Documentation 🕐 10-20 Minutes

Grey Divider

AI Description

• Switch release automation to use konflux-bot-0/1 service accounts
• Replace legacy rhtas-build-bot and CAC deployer RBAC with new manifests
• Update kustomizations and README to reference the new service account names
Diagram

graph TD
README["README"] --> DOCS["Docs: SA names"] --> SA0["SA/RBAC: konflux-bot-0"] & SA1["SA/RBAC: konflux-bot-1"]
KSA["service-account kustomization"] --> SA0 --> RPP["Project/App ReleasePlan refs"]
KRL["konflux-manifests kustomization"] --> SA1 --> RPL["Konflux releaseplan"]
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Keep old service accounts as aliases during transition
  • ➕ Reduces blast radius if any external references still point to old SA names
  • ➕ Allows phased migration across tenants/environments
  • ➖ Leaves legacy RBAC in place longer (larger attack surface)
  • ➖ Adds maintenance burden and ambiguity about which SA is canonical
2. Use a single shared ServiceAccount with grouped permissions
  • ➕ Fewer moving pieces and fewer names to keep consistent across ReleasePlans
  • ➕ Simplifies docs and operational runbooks
  • ➖ Broader permissions for one identity (less least-privilege)
  • ➖ Harder to audit which automation path performed an action
3. Parameterize serviceAccountName via kustomize overlays
  • ➕ Allows different SA names per environment without patch duplication
  • ➕ Eases future rotations/migrations
  • ➖ Introduces additional indirection for reviewers/operators
  • ➖ Requires consistent overlay conventions across all bases

Recommendation: The PR’s direct rename-and-rewire approach is appropriate if this repo is the single source of truth for SA names and consumers. Consider a temporary alias/compatibility SA only if there are known external references to the legacy names; otherwise, removing the old manifests and updating all ReleasePlan references (as done here) keeps the configuration clean and unambiguous.

Files changed (10) +27 / -23

Documentation (1) +4 / -5
README.mdUpdate docs to reference konflux-bot service accounts +4/-5

Update docs to reference konflux-bot service accounts

• Replaces legacy service account names in operational steps and pipeline documentation with the new konflux-bot-0/1 names. Updates the referenced manifest location for the CAC deployer service account.

konflux-configs/README.md

Other (9) +23 / -18
releaseplan.yamlUse konflux-bot-0 for promote-to-candidate ReleasePlan +1/-1

Use konflux-bot-0 for promote-to-candidate ReleasePlan

• Updates the ReleasePlan to run the tenant pipeline using serviceAccountName konflux-bot-0 instead of rhtas-build-bot.

konflux-configs/base/application/base/promote-to-candidate/releaseplan.yaml

component.yamlSwitch component ReleasePlan patch to konflux-bot-0 +1/-1

Switch component ReleasePlan patch to konflux-bot-0

• Changes the patched tenantPipeline.serviceAccountName to konflux-bot-0 to align with the new service account naming.

konflux-configs/base/project/base/release-plan/patch/component.yaml

fbc.yamlSwitch FBC ReleasePlan patch to konflux-bot-0 +1/-1

Switch FBC ReleasePlan patch to konflux-bot-0

• Updates the FBC release-plan patch so the pipeline runs under konflux-bot-0 rather than rhtas-build-bot.

konflux-configs/base/project/base/release-plan/patch/fbc.yaml

operator.yamlSwitch operator ReleasePlan patch to konflux-bot-0 +1/-1

Switch operator ReleasePlan patch to konflux-bot-0

• Updates the operator release-plan patch to use konflux-bot-0 for tenantPipeline execution.

konflux-configs/base/project/base/release-plan/patch/operator.yaml

konflux-bot-1.yamlRename CAC deployer SA/RBAC to konflux-bot-1 and relabel +7/-5

Rename CAC deployer SA/RBAC to konflux-bot-1 and relabel

• Renames the ServiceAccount, Role, and RoleBinding from the legacy CAC deployer names to konflux-bot-1 equivalents. Adds a label to preserve grouping/identity metadata for the migrated service account.

konflux-configs/base/release-plan/konflux-manifests/base/konflux-bot-1.yaml

kustomization.yamlReplace rbac.yaml resource with konflux-bot-1 manifest +1/-1

Replace rbac.yaml resource with konflux-bot-1 manifest

• Updates the kustomization resources list to include konflux-bot-1.yaml instead of the previous rbac.yaml file.

konflux-configs/base/release-plan/konflux-manifests/base/kustomization.yaml

releaseplan.yamlRun Konflux manifests ReleasePlan with konflux-bot-1 +1/-1

Run Konflux manifests ReleasePlan with konflux-bot-1

• Switches tenantPipeline.serviceAccountName to konflux-bot-1 for the configuration-as-code deployment pipeline.

konflux-configs/base/release-plan/konflux-manifests/base/releaseplan.yaml

konflux-bot-0.yamlRename build-bot SA/RBAC to konflux-bot-0 and add pull secret +9/-5

Rename build-bot SA/RBAC to konflux-bot-0 and add pull secret

• Renames the tenant ServiceAccount/Role/RoleBinding from rhtas-build-bot to konflux-bot-0. Adds labels for SA grouping and configures an imagePullSecret for registry-redhat-io access.

konflux-configs/base/service-account/konflux-bot-0.yaml

kustomization.yamlConsolidate service-account resources to konflux-bot-0 +1/-2

Consolidate service-account resources to konflux-bot-0

• Replaces the previous promote/release service account resources with the new consolidated konflux-bot-0 manifest in the kustomization.

konflux-configs/base/service-account/kustomization.yaml

@qodo-for-securesign

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (1) 📘 Rule violations (0) 📜 Skill insights (0)

Grey Divider


Remediation recommended

1. RoleBinding subject namespace missing 🐞 Bug ☼ Reliability
Description
konflux-bot-1-rolebinding’s ServiceAccount subject omits namespace, so the binding does not
explicitly target konflux-bot-1 in the intended tenant namespace. This can result in the
ReleasePlan using konflux-bot-1 running without the intended RBAC if the subject namespace is not
defaulted/injected during rendering.
Code

konflux-configs/base/release-plan/konflux-manifests/base/konflux-bot-1.yaml[R29-34]

metadata:
-  name: konflux-configuration-as-code-deployer-rolebinding
+  name: konflux-bot-1-rolebinding
subjects:
  - kind: ServiceAccount
-    name: konflux-configuration-as-code-deployer
+    name: konflux-bot-1
roleRef:
Relevance

⭐⭐ Medium

Repo previously merged RoleBinding SA subjects without namespace, so enforcement is unclear despite
potential RBAC ambiguity.

PR-#244

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The new konflux-bot-1 RoleBinding subject has no namespace, while other RBAC in this repo
includes namespace for ServiceAccount subjects (including the migrated konflux-bot-0 RoleBinding
and an in-repo ClusterRoleBinding manifest), indicating the intended/expected pattern is to
explicitly set it. The overlays also set a namespace at the kustomization level, so the subject
should unambiguously target that namespace after rendering.

konflux-configs/base/release-plan/konflux-manifests/base/konflux-bot-1.yaml[27-37]
konflux-configs/base/service-account/konflux-bot-0.yaml[25-37]
tasks/integration-test/install-operator-from-fbc-olm-v1.yaml[88-107]
konflux-configs/overlay/prod/kustomization.yaml[1-12]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
`konflux-configs/base/release-plan/konflux-manifests/base/konflux-bot-1.yaml` defines a `RoleBinding` whose `subjects` entry for the `ServiceAccount` lacks a `namespace`. In this repo, ServiceAccount subjects are consistently namespaced, and omitting it risks the RoleBinding not applying to the intended ServiceAccount in the tenant namespace.

### Issue Context
These resources are applied via Kustomize overlays that set a namespace (e.g., `overlay/prod`, `overlay/dev`). Ensure the RoleBinding subject continues to match the ServiceAccount namespace after Kustomize rendering.

### Fix Focus Areas
- konflux-configs/base/release-plan/konflux-manifests/base/konflux-bot-1.yaml[27-37]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

@JasonPowr
JasonPowr requested a review from osmman July 24, 2026 09:12
@JasonPowr
JasonPowr merged commit c623b66 into main Jul 24, 2026
4 checks passed
@JasonPowr
JasonPowr deleted the sa-migration branch July 24, 2026 09:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants