Restore shared oauth-credentials rule to its default-SA scope
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful

This commit is contained in:
2026-09-28 22:44:39 +10:00
parent 65034b9189
commit 141dd25798
@@ -1,11 +1,10 @@
# Allow the Terraform Authentik runner to read the OAuth2/OIDC client secret that
# backs an authentik provider, in whichever namespace the target service lives
# (the module's data.vault_kv_secret_v2). The literal + is a Vault single-segment
# wildcard: one oauth-credentials secret per service account, so a namespace can
# host several OIDC apps as long as each runs under its own service account.
# wildcard: one oauth-credentials secret per onboarded namespace.
---
rules:
- path: "kv/data/kubernetes/namespace/+/+/oauth-credentials"
- path: "kv/data/kubernetes/namespace/+/default/oauth-credentials"
capabilities:
- read