From 31a7abec999ceb4ae46a5d4999d98143dd4ead9e Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Wed, 19 Aug 2026 22:54:13 +1000 Subject: [PATCH] vault: add arrstack policies (deployer + KV read + creds) (2/3) (#126) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ## Why Grants the Vault access the arrstack engine needs, before any engine resources exist. **PR 2 of 3 (policy)**, stacked on #125 (register). Keeping policy separate from resources honours the never-bundle / sequential-apply rule. ## Change - Adds `policies/arrstack/admin.yaml`: the terraform-vault deployer (`tf_vault` approle + `woodpecker_terraform_vault` k8s role) may create/read/update/delete `arrstack/config` and manage `arrstack/roles/*`. - Adds `policies/kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token/read.yaml`: the deployer may read the KV-seeded arrproxy admin token (both `kv/data/...` and `kv/metadata/...`) that the engine config sources. The existing `secret_backends_read` policy does not cover this `kubernetes/namespace` KV path. - Adds `policies/arrstack/creds/{sonarr,radarr,prowlarr}.yaml`: each `terraform-` run may read its own `arrstack/creds/` to mint a scoped key. - Policy YAMLs are auto-discovered by `policies/policies.hcl`, so no wiring changes are needed. ## Apply order Apply **after PR #125 (register)**. Safe to apply before the engine exists — these only grant capabilities on paths. ## Stack 1. register -> #125 2. **policy (this PR)** -> `benvin/arrstack-policy` off `benvin/arrstack-register` 3. resources -> `benvin/arrstack-resources` Supersedes #124. Reviewed-on: https://git.unkin.net/unkin/terraform-vault/pulls/126 Co-authored-by: unkin-agent Co-committed-by: unkin-agent --- policies/arrstack/admin.yaml | 27 +++++++++++++++++++ policies/arrstack/creds/prowlarr.yaml | 12 +++++++++ policies/arrstack/creds/radarr.yaml | 12 +++++++++ policies/arrstack/creds/sonarr.yaml | 12 +++++++++ .../default/arrproxy-admin-token/read.yaml | 22 +++++++++++++++ 5 files changed, 85 insertions(+) create mode 100644 policies/arrstack/admin.yaml create mode 100644 policies/arrstack/creds/prowlarr.yaml create mode 100644 policies/arrstack/creds/radarr.yaml create mode 100644 policies/arrstack/creds/sonarr.yaml create mode 100644 policies/kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token/read.yaml diff --git a/policies/arrstack/admin.yaml b/policies/arrstack/admin.yaml new file mode 100644 index 0000000..96b86d8 --- /dev/null +++ b/policies/arrstack/admin.yaml @@ -0,0 +1,27 @@ +# Allow management of the arrstack secrets engine (config and roles) by the +# terraform-vault deployer. +--- +rules: + - path: "arrstack/config" + capabilities: + - create + - update + - read + - delete + - path: "arrstack/roles/*" + capabilities: + - create + - update + - delete + - read + - list + - path: "arrstack/roles" + capabilities: + - read + - list + +auth: + approle: + - tf_vault + k8s/au/syd1: + - woodpecker_terraform_vault diff --git a/policies/arrstack/creds/prowlarr.yaml b/policies/arrstack/creds/prowlarr.yaml new file mode 100644 index 0000000..5922685 --- /dev/null +++ b/policies/arrstack/creds/prowlarr.yaml @@ -0,0 +1,12 @@ +# Allow the terraform-prowlarr run to mint a Prowlarr-scoped arrproxy key. +--- +rules: + - path: "arrstack/creds/prowlarr" + capabilities: + - read + +auth: + approle: + - terraform_prowlarr + k8s/au/syd1: + - woodpecker_terraform_prowlarr diff --git a/policies/arrstack/creds/radarr.yaml b/policies/arrstack/creds/radarr.yaml new file mode 100644 index 0000000..7b79acf --- /dev/null +++ b/policies/arrstack/creds/radarr.yaml @@ -0,0 +1,12 @@ +# Allow the terraform-radarr run to mint a Radarr-scoped arrproxy key. +--- +rules: + - path: "arrstack/creds/radarr" + capabilities: + - read + +auth: + approle: + - terraform_radarr + k8s/au/syd1: + - woodpecker_terraform_radarr diff --git a/policies/arrstack/creds/sonarr.yaml b/policies/arrstack/creds/sonarr.yaml new file mode 100644 index 0000000..5e5ae54 --- /dev/null +++ b/policies/arrstack/creds/sonarr.yaml @@ -0,0 +1,12 @@ +# Allow the terraform-sonarr run to mint a Sonarr-scoped arrproxy key. +--- +rules: + - path: "arrstack/creds/sonarr" + capabilities: + - read + +auth: + approle: + - terraform_sonarr + k8s/au/syd1: + - woodpecker_terraform_sonarr diff --git a/policies/kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token/read.yaml b/policies/kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token/read.yaml new file mode 100644 index 0000000..66d1547 --- /dev/null +++ b/policies/kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token/read.yaml @@ -0,0 +1,22 @@ +# Allow the terraform-vault deployer to read the seeded arrproxy admin token so +# the arrstack engine config module can source it. The token is seeded by +# argocd-apps #384 at kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token. +# The deployer's existing secret_backends_read policy only covers +# kv/data/service/vault/+/+/secret_backend/*, which does not match this +# kubernetes/namespace path, so this adds the minimal read grant rather than +# duplicating the secret into the litellm-style path. vault_kv_secret_v2 also +# reads the kv-v2 metadata path on every plan/apply, so grant that too. +--- +rules: + - path: "kv/data/kubernetes/namespace/arrstack/default/arrproxy-admin-token" + capabilities: + - read + - path: "kv/metadata/kubernetes/namespace/arrstack/default/arrproxy-admin-token" + capabilities: + - read + +auth: + approle: + - tf_vault + k8s/au/syd1: + - woodpecker_terraform_vault