feat: add policy to read terraform vars

- read variables required for terraform-repoflow
This commit is contained in:
Ben Vincent 2025-12-13 10:56:58 +11:00
parent 65ad53e24c
commit 4f185d5e28
2 changed files with 4 additions and 0 deletions

View File

@ -4,6 +4,7 @@ resource "vault_approle_auth_backend_role" "terraform_repoflow" {
token_policies = [
"default_access",
"kv/service/repoflow/unkinadmin/tokens/terraform/read",
"kv/service/terraform/repoflow",
]
token_ttl = 60
token_max_ttl = 120

View File

@ -0,0 +1,3 @@
path "kv/data/service/terraform/repoflow" {
capabilities = ["read"]
}