1485962cf5
The terraform-authentik runner's Vault policy only grants read on kv/data/kubernetes/namespace/+/default/oauth-credentials (literal trailing filename), so the arrstack/default/mediamark-oauth-credentials path 403s at plan time and reddens CI. mediamark deploys in its own `mediamark` namespace (watchstate model), so point the data source at kubernetes/namespace/mediamark/default/oauth-credentials, which the policy covers. Hostnames are unchanged. Rename the permission group to akP-mediamark-user to match the peer tier-suffix convention (akP-watchstate-admin, akP-arrstack-user). The group name is derived from the filename in config/config.hcl, so update the akR-media-adult reference too.
5 lines
189 B
YAML
5 lines
189 B
YAML
# Permission group akP-mediamark-user (name = filename). Grants user access to
|
|
# mediamark: bound to the mediamark application, gating the kids-content
|
|
# marking UI.
|
|
application: mediamark
|