In order to keep the pre-shared nature of NBSetupKey alive i propose two setup mechanisms for the new SetupKey CRD:
- The current implementation wich relies on API access
- A secretRef variant which allows to provide pre created setup key
This will keep the option to not provide the operator with API access and drop the need to rorate PATs
In order to keep the pre-shared nature of NBSetupKey alive i propose two setup mechanisms for the new SetupKey CRD:
This will keep the option to not provide the operator with API access and drop the need to rorate PATs