Grant agents approle read on kv/service/authentik/agent-api-token
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful

Automation seeds oauth client secrets and LDAP outpost tokens; fetching
outpost tokens needs a scoped Authentik API token, seeded at this path
by the operator.
This commit is contained in:
2026-08-29 12:08:26 +10:00
parent 36d2b99255
commit 7a6aa7e2ec
@@ -0,0 +1,14 @@
# Lets the agents AppRole read a dedicated, scoped Authentik API token seeded by
# the operator. Automation seeds OAuth2 client secrets and LDAP outpost tokens as
# part of normal IaC workflows; fetching an outpost token requires calling the
# Authentik API, so a scoped token (not the CI admin credential) is read here.
# Mirrors the gitea/creds/unkin-agent agents-approle read grant pattern.
---
rules:
- path: "kv/data/service/authentik/agent-api-token"
capabilities:
- read
auth:
approle:
- agents