Skip to content

feat(scout): remote endpoint mode with file-based credentials — roadmap 12 complete (ADR-0008) - #514

Merged
ebourgeois merged 1 commit into
mainfrom
scout-ingress
Sep 29, 2026
Merged

ebourgeois merged 1 commit into
mainfrom
scout-ingress

Conversation

@ebourgeois

Copy link
Copy Markdown
Contributor

feat(scout): remote endpoint mode with file-based credentials — roadmap 12 complete (ADR-0008)

…ap 12 complete (ADR-0008)

Adds BINDY_SCOUT_REMOTE_ENDPOINT/_TOKEN_FILE/_CA_FILE (+ CLI flags) as a
peer to the Phase 2 kubeconfig Secret: fail-closed mode selection, client
built via a synthesized kubeconfig so kube-rs re-reads the token on
rotation. ADR-0008 corrects Phase 3's premise — the API server is not
meshed (Linkerd mTLS needs a mirrored meshed proxy) and the credential
must be minted by the bindy cluster (ADR-0002). Scout guide documents the
Linkerd multicluster pattern; its stale roadmap table is fixed; surviving
follow-ups move to roadmap 27. Threat model v1.6 (M-32).

Signed-off-by: Erick Bourgeois <erick@jeb.ca>
@ebourgeois
ebourgeois merged commit 48f5fcc into main Sep 29, 2026
46 checks passed
@ebourgeois
ebourgeois deleted the scout-ingress branch September 29, 2026 01:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant