Add terraform-enc auth, consul state role, and encapi token grant
The new terragrunt-enc repo manages all encapi ENC data via Terraform and needs its own Vault/Consul plumbing, mirroring terraform-git/terraform-incus: CI auth, isolated consul state, and read access to the ENCAPI_WRITE_TOKEN. - Add approle role terraform_enc and k8s auth role woodpecker_terraform_enc (bound to the terraform-enc SA in the woodpecker namespace). - Add consul secret backend role + ACL rules granting write on infra/terraform/enc/ for its terragrunt state, plus a policy letting both auth roles read consul_root/au/syd1/creds/terraform-enc. - Grant both auth roles read on kv/data/kubernetes/namespace/encapi/default/environment (ENCAPI_WRITE_TOKEN).
This commit is contained in:
@@ -0,0 +1,7 @@
|
||||
bound_service_account_names:
|
||||
- terraform-enc
|
||||
bound_service_account_namespaces:
|
||||
- woodpecker
|
||||
token_ttl: 600
|
||||
token_max_ttl: 600
|
||||
audience: https://kubernetes.default.svc.cluster.local
|
||||
Reference in New Issue
Block a user