policies: grant the vault deployer access to the gitea secrets engine
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful

Why: applying the forthcoming gitea_secret_backend + role config from
terraform-vault requires the deployment identity (tf_vault approle /
woodpecker_terraform_vault k8s role) to write the engine's config and roles.
Without it, the engine apply 403s. This mirrors policies/rancher/admin.yaml.

Change:
- Add policies/gitea/admin.yaml granting create/read/update/delete on
  gitea/config, create/update on gitea/config/rotate-root, and full manage
  on gitea/roles/*; excludes gitea/creds/* (minting is for consumers).
- Catalog registration is already covered by the shared wildcard grant in
  policies/sys/plugins/catalog/admin.yaml and mounting uses existing
  sys/mounts/* access, so no new catalog/mount grant is added (matches rancher).

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
This commit is contained in:
2026-07-27 19:02:08 +10:00
parent 31424ea6ff
commit 724fcf2a76
+42
View File
@@ -0,0 +1,42 @@
# Allow the vault deployer to manage the gitea token secrets engine: its
# connection config (seeded admin credentials), in-place root rotation, and
# token-minting roles.
#
# Scoped to gitea/* only, and deliberately excludes gitea/creds/* — minting
# tokens is for consumers, not the deployer. The plugin-catalog grant needed to
# import the plugin is the shared, sudo-protected wildcard in
# policies/sys/plugins/catalog/admin.yaml (already covers this plugin), and
# mounting the engine uses the deployer's existing sys/mounts/* access, so no
# new catalog/mount grant is added here (mirrors the rancher engine).
---
rules:
# Engine connection config (Gitea URL, TLS, seeded admin username/password).
- path: "gitea/config"
capabilities:
- create
- read
- update
- delete
# In-place rotation of the seeded admin password (write-only trigger).
- path: "gitea/config/rotate-root"
capabilities:
- create
- update
# Token-minting roles.
- path: "gitea/roles/*"
capabilities:
- create
- read
- update
- delete
- list
- path: "gitea/roles"
capabilities:
- read
- list
auth:
approle:
- tf_vault
k8s/au/syd1:
- woodpecker_terraform_vault