From 4f185d5e287c5580762b3b7b8974230ff5b052ac Mon Sep 17 00:00:00 2001 From: Ben Vincent Date: Sat, 13 Dec 2025 10:56:58 +1100 Subject: [PATCH] feat: add policy to read terraform vars - read variables required for terraform-repoflow --- auth_approle_terraform_repoflow.tf | 1 + policies/kv/service/terraform/repoflow.hcl | 3 +++ 2 files changed, 4 insertions(+) create mode 100644 policies/kv/service/terraform/repoflow.hcl diff --git a/auth_approle_terraform_repoflow.tf b/auth_approle_terraform_repoflow.tf index 9c7bf15..96b7176 100644 --- a/auth_approle_terraform_repoflow.tf +++ b/auth_approle_terraform_repoflow.tf @@ -4,6 +4,7 @@ resource "vault_approle_auth_backend_role" "terraform_repoflow" { token_policies = [ "default_access", "kv/service/repoflow/unkinadmin/tokens/terraform/read", + "kv/service/terraform/repoflow", ] token_ttl = 60 token_max_ttl = 120 diff --git a/policies/kv/service/terraform/repoflow.hcl b/policies/kv/service/terraform/repoflow.hcl new file mode 100644 index 0000000..d07a5bd --- /dev/null +++ b/policies/kv/service/terraform/repoflow.hcl @@ -0,0 +1,3 @@ +path "kv/data/service/terraform/repoflow" { + capabilities = ["read"] +}