Merge pull request 'feat: add repoflow service vault configuration' (#39) from benvin/repoflow into master
Reviewed-on: #39
This commit is contained in:
commit
65ad53e24c
@ -95,3 +95,23 @@ resource "vault_kubernetes_auth_backend_role" "media-apps" {
|
||||
]
|
||||
audience = "vault"
|
||||
}
|
||||
|
||||
resource "vault_kubernetes_auth_backend_role" "repoflow" {
|
||||
backend = vault_auth_backend.kubernetes.path
|
||||
role_name = "repoflow"
|
||||
bound_service_account_names = [
|
||||
"default",
|
||||
]
|
||||
bound_service_account_namespaces = [
|
||||
"repoflow",
|
||||
]
|
||||
token_ttl = 60
|
||||
token_policies = [
|
||||
"kv/service/repoflow/au/syd1/ceph-s3/read",
|
||||
"kv/service/repoflow/au/syd1/elasticsearch/read",
|
||||
"kv/service/repoflow/au/syd1/hasura/read",
|
||||
"kv/service/repoflow/au/syd1/postgres/read",
|
||||
"kv/service/repoflow/au/syd1/repoflow-server/read",
|
||||
]
|
||||
audience = "vault"
|
||||
}
|
||||
|
||||
3
policies/kv/service/repoflow/au/syd1/ceph-s3/read.hcl
Normal file
3
policies/kv/service/repoflow/au/syd1/ceph-s3/read.hcl
Normal file
@ -0,0 +1,3 @@
|
||||
path "kv/data/service/repoflow/au/syd1/ceph-s3" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
@ -0,0 +1,3 @@
|
||||
path "kv/data/service/repoflow/au/syd1/elasticsearch" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
3
policies/kv/service/repoflow/au/syd1/hasura/read.hcl
Normal file
3
policies/kv/service/repoflow/au/syd1/hasura/read.hcl
Normal file
@ -0,0 +1,3 @@
|
||||
path "kv/data/service/repoflow/au/syd1/hasura" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
3
policies/kv/service/repoflow/au/syd1/postgres/read.hcl
Normal file
3
policies/kv/service/repoflow/au/syd1/postgres/read.hcl
Normal file
@ -0,0 +1,3 @@
|
||||
path "kv/data/service/repoflow/au/syd1/postgres" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
@ -0,0 +1,3 @@
|
||||
path "kv/data/service/repoflow/au/syd1/repoflow-server" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
Loading…
Reference in New Issue
Block a user