Fix mediamark Vault secret path and permission group name
The terraform-authentik runner's Vault policy only grants read on kv/data/kubernetes/namespace/+/default/oauth-credentials (literal trailing filename), so the arrstack/default/mediamark-oauth-credentials path 403s at plan time and reddens CI. mediamark deploys in its own `mediamark` namespace (watchstate model), so point the data source at kubernetes/namespace/mediamark/default/oauth-credentials, which the policy covers. Hostnames are unchanged. Rename the permission group to akP-mediamark-user to match the peer tier-suffix convention (akP-watchstate-admin, akP-arrstack-user). The group name is derived from the filename in config/config.hcl, so update the akR-media-adult reference too.
This commit is contained in:
@@ -0,0 +1,4 @@
|
||||
# Permission group akP-mediamark-user (name = filename). Grants user access to
|
||||
# mediamark: bound to the mediamark application, gating the kids-content
|
||||
# marking UI.
|
||||
application: mediamark
|
||||
@@ -1,3 +0,0 @@
|
||||
# Permission group akP-mediamark (name = filename). Grants access to mediamark:
|
||||
# bound to the mediamark application, gating the kids-content marking UI.
|
||||
application: mediamark
|
||||
Reference in New Issue
Block a user