Add arrstack Vault policies (deployer, KV read, consumer creds)
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful

Grant the Vault access the arrstack engine needs, before any engine
resources exist. Second of three stacked steps (register -> policy ->
resources).

Adds:
- policies/arrstack/admin.yaml: the terraform-vault deployer may
  create/read/update/delete arrstack/config and manage arrstack/roles/*.
- policies/kv/.../arrproxy-admin-token/read.yaml: the deployer may read
  the KV-seeded arrproxy admin token (data + metadata paths) that the
  engine config sources; the existing secret_backends_read policy does
  not cover this kubernetes/namespace KV path.
- policies/arrstack/creds/{sonarr,radarr,prowlarr}.yaml: each terraform-
  <app> run may read its own arrstack/creds/<app> to mint a scoped key.

Policy YAMLs are auto-discovered by policies/policies.hcl, so no wiring
changes are needed.

Apply order: after PR-1 (register). Safe to apply before the engine
exists since these only grant capabilities on paths.
This commit is contained in:
2026-08-19 21:38:28 +10:00
parent f0a61dc352
commit 5862ae974c
5 changed files with 85 additions and 0 deletions
+27
View File
@@ -0,0 +1,27 @@
# Allow management of the arrstack secrets engine (config and roles) by the
# terraform-vault deployer.
---
rules:
- path: "arrstack/config"
capabilities:
- create
- update
- read
- delete
- path: "arrstack/roles/*"
capabilities:
- create
- update
- delete
- read
- list
- path: "arrstack/roles"
capabilities:
- read
- list
auth:
approle:
- tf_vault
k8s/au/syd1:
- woodpecker_terraform_vault
+12
View File
@@ -0,0 +1,12 @@
# Allow the terraform-prowlarr run to mint a Prowlarr-scoped arrproxy key.
---
rules:
- path: "arrstack/creds/prowlarr"
capabilities:
- read
auth:
approle:
- terraform_prowlarr
k8s/au/syd1:
- woodpecker_terraform_prowlarr
+12
View File
@@ -0,0 +1,12 @@
# Allow the terraform-radarr run to mint a Radarr-scoped arrproxy key.
---
rules:
- path: "arrstack/creds/radarr"
capabilities:
- read
auth:
approle:
- terraform_radarr
k8s/au/syd1:
- woodpecker_terraform_radarr
+12
View File
@@ -0,0 +1,12 @@
# Allow the terraform-sonarr run to mint a Sonarr-scoped arrproxy key.
---
rules:
- path: "arrstack/creds/sonarr"
capabilities:
- read
auth:
approle:
- terraform_sonarr
k8s/au/syd1:
- woodpecker_terraform_sonarr
@@ -0,0 +1,22 @@
# Allow the terraform-vault deployer to read the seeded arrproxy admin token so
# the arrstack engine config module can source it. The token is seeded by
# argocd-apps #384 at kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token.
# The deployer's existing secret_backends_read policy only covers
# kv/data/service/vault/+/+/secret_backend/*, which does not match this
# kubernetes/namespace path, so this adds the minimal read grant rather than
# duplicating the secret into the litellm-style path. vault_kv_secret_v2 also
# reads the kv-v2 metadata path on every plan/apply, so grant that too.
---
rules:
- path: "kv/data/kubernetes/namespace/arrstack/default/arrproxy-admin-token"
capabilities:
- read
- path: "kv/metadata/kubernetes/namespace/arrstack/default/arrproxy-admin-token"
capabilities:
- read
auth:
approle:
- tf_vault
k8s/au/syd1:
- woodpecker_terraform_vault