Restore shared oauth-credentials rule to its default-SA scope
This commit is contained in:
+2
-3
@@ -1,11 +1,10 @@
|
||||
# Allow the Terraform Authentik runner to read the OAuth2/OIDC client secret that
|
||||
# backs an authentik provider, in whichever namespace the target service lives
|
||||
# (the module's data.vault_kv_secret_v2). The literal + is a Vault single-segment
|
||||
# wildcard: one oauth-credentials secret per service account, so a namespace can
|
||||
# host several OIDC apps as long as each runs under its own service account.
|
||||
# wildcard: one oauth-credentials secret per onboarded namespace.
|
||||
---
|
||||
rules:
|
||||
- path: "kv/data/kubernetes/namespace/+/+/oauth-credentials"
|
||||
- path: "kv/data/kubernetes/namespace/+/default/oauth-credentials"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
Reference in New Issue
Block a user