Scope shared oauth-credentials policy per service account
This commit is contained in:
+3
-2
@@ -1,10 +1,11 @@
|
||||
# Allow the Terraform Authentik runner to read the OAuth2/OIDC client secret that
|
||||
# backs an authentik provider, in whichever namespace the target service lives
|
||||
# (the module's data.vault_kv_secret_v2). The literal + is a Vault single-segment
|
||||
# wildcard: one oauth-credentials secret per onboarded namespace.
|
||||
# wildcard: one oauth-credentials secret per service account, so a namespace can
|
||||
# host several OIDC apps as long as each runs under its own service account.
|
||||
---
|
||||
rules:
|
||||
- path: "kv/data/kubernetes/namespace/+/default/oauth-credentials"
|
||||
- path: "kv/data/kubernetes/namespace/+/+/oauth-credentials"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
@@ -1,14 +0,0 @@
|
||||
# Allow the Terraform Authentik runner to read the vlogs OIDC client secret. It is
|
||||
# a second OIDC client in an already-onboarded namespace, so it cannot use the
|
||||
# one-per-namespace oauth-credentials path.
|
||||
---
|
||||
rules:
|
||||
- path: "kv/data/kubernetes/namespace/logging/default/vlogs-oauth-credentials"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- terraform_authentik
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_authentik
|
||||
Reference in New Issue
Block a user