Skip to content

Add source-watcher to multi-tenancy docs - #2666

Merged
matheuscscp merged 1 commit into
mainfrom
source-watcher-multitenancy-flags
Oct 2, 2026
Merged

matheuscscp merged 1 commit into
mainfrom
source-watcher-multitenancy-flags

Conversation

@matheuscscp

@matheuscscp matheuscscp commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Documents the source-watcher flags relevant to multi-tenancy lockdown:

  • --no-cross-namespace-refs added to the multi-tenancy lockdown best practices and to the bootstrap patch targets.
  • --default-service-account added to the Kubernetes RBAC impersonation best practices, supported starting with Flux v2.10.0. For source-watcher, it only applies to ExternalArtifact resources that target a namespace other than the ArtifactGenerator namespace; artifacts in the ArtifactGenerator namespace continue to be reconciled with the controller's service account.

The multi-tenancy bootstrap patch includes a note about the Flux v2.10.0 minimum version for the source-watcher --default-service-account flag, since earlier controller versions fail to start with an unknown flag.

The workload identity section now clarifies that source-watcher's --default-service-account is used for Kubernetes RBAC impersonation, not for workload identity authentication.

xref: fluxcd/source-watcher#354 fluxcd/source-watcher#387

Document that source-watcher accepts the --no-cross-namespace-refs flag
and, starting with Flux v2.10.0, the --default-service-account flag for
reconciling ExternalArtifacts in namespaces other than the
ArtifactGenerator namespace.

Signed-off-by: Matheus Pimenta <matheuscscp@gmail.com>
@matheuscscp
matheuscscp force-pushed the source-watcher-multitenancy-flags branch from 0d22513 to 32241a2 Compare October 1, 2026 11:20
@matheuscscp matheuscscp added area/docs Documentation related issues and pull requests enhancement New feature or request area/security Security related issues and pull requests labels Oct 1, 2026

@stefanprodan stefanprodan left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@matheuscscp
matheuscscp merged commit 526e1d4 into main Oct 2, 2026
8 checks passed
@matheuscscp
matheuscscp deleted the source-watcher-multitenancy-flags branch October 2, 2026 14:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/docs Documentation related issues and pull requests area/security Security related issues and pull requests enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants