Add terraform-enc auth, consul state role, and encapi token grant
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/plan Pipeline was successful

The new terragrunt-enc repo manages all encapi ENC data via Terraform and
needs its own Vault/Consul plumbing, mirroring terraform-git/terraform-incus:
CI auth, isolated consul state, and read access to the ENCAPI_WRITE_TOKEN.

- Add approle role terraform_enc and k8s auth role woodpecker_terraform_enc
  (bound to the terraform-enc SA in the woodpecker namespace).
- Add consul secret backend role + ACL rules granting write on
  infra/terraform/enc/ for its terragrunt state, plus a policy letting both
  auth roles read consul_root/au/syd1/creds/terraform-enc.
- Grant both auth roles read on
  kv/data/kubernetes/namespace/encapi/default/environment (ENCAPI_WRITE_TOKEN).
This commit is contained in:
2026-07-24 23:05:55 +10:00
parent dcc73131a4
commit 6d90d90b66
6 changed files with 56 additions and 0 deletions
@@ -0,0 +1,14 @@
# Allow the terragrunt-enc runner to generate credentials for the
# terraform-enc role in consul (used to lock/write its terragrunt state under
# infra/terraform/enc/ on the consul backend).
---
rules:
- path: "consul_root/au/syd1/creds/terraform-enc"
capabilities:
- read
auth:
approle:
- terraform_enc
k8s/au/syd1:
- woodpecker_terraform_enc
@@ -0,0 +1,14 @@
# Allow the terragrunt-enc runner to read the encapi environment secret
# (ENCAPI_WRITE_TOKEN), so `make apply` can write ENC data (statuses, roles,
# nodes) to encapi via the encapi Terraform provider.
---
rules:
- path: "kv/data/kubernetes/namespace/encapi/default/environment"
capabilities:
- read
auth:
approle:
- terraform_enc
k8s/au/syd1:
- woodpecker_terraform_enc