I think svc accounts shouldn't have k-space:floor on them. It also complicates billing (if access then bill).
Does removing them hurt deliverability? Probably no?
Impersonate wouldn't work, k-space:friends is an option, in theory, or just k-space:mailservice new / separate role?

I think svc accounts shouldn't have `k-space:floor` on them. It also complicates billing (if access then bill).
1. Does removing them hurt deliverability? Probably no?
2. Impersonate wouldn't work, `k-space:friends` is an option, in theory, or just `k-space:mailservice` new / separate role?
Wildduck components have k-space:floor whitelisted here and there but it shouldn't matter as none of those account are meant to access any ingress. And these are arbitrary groups so just change those to proposed k-space:mailservice but add that group here
Wildduck components have k-space:floor whitelisted here and there but it shouldn't matter as none of those account are meant to access any ingress. And these are arbitrary groups so just change those to proposed k-space:mailservice but add that group here https://git.k-space.ee/k-space/kube/src/commit/f82caf175148a87811b0a906461b4364729ae069/wildduck/wildduck-operator.yaml#L25
Closed with https://git.k-space.ee/k-space/kube/commit/ce2e6568b1bc7f4a863a21a02fca3f9e4053d06b and https://git.k-space.ee/k-space/members/commit/96ea54064cc4ccd7b6616acf5c9bbed761af8db3
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
I think svc accounts shouldn't have
k-space:flooron them. It also complicates billing (if access then bill).k-space:friendsis an option, in theory, or justk-space:mailservicenew / separate role?Wildduck components have k-space:floor whitelisted here and there but it shouldn't matter as none of those account are meant to access any ingress. And these are arbitrary groups so just change those to proposed k-space:mailservice but add that group here
Closed with
ce2e6568b1and96ea54064c