From 7aaafb455d4433dea3497e327babc46470a5947e Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sun, 30 Aug 2026 22:01:07 +1000 Subject: [PATCH] Drop the deployer capability policies extracted to #148 Review ruled that shipping the auth/oidc and identity-group grants alongside the resources they authorise violates the never-bundle rule: AppRole capabilities are fixed at login, so the grants must land in a prior apply. Remove policies/auth/oidc/admin.yaml and policies/identity/group/admin.yaml; they now ship unchanged in #148, which merges and applies first. --- policies/auth/oidc/admin.yaml | 19 --------------- policies/identity/group/admin.yaml | 38 ------------------------------ 2 files changed, 57 deletions(-) delete mode 100644 policies/auth/oidc/admin.yaml delete mode 100644 policies/identity/group/admin.yaml diff --git a/policies/auth/oidc/admin.yaml b/policies/auth/oidc/admin.yaml deleted file mode 100644 index 9f04b3b..0000000 --- a/policies/auth/oidc/admin.yaml +++ /dev/null @@ -1,19 +0,0 @@ -# Allow full administration of the OIDC auth backend (mount config and login -# roles), mirroring policies/auth/ldap/admin.yaml. sys/auth/* already covers -# enabling the mount itself; this covers writing auth/oidc/config and -# auth/oidc/role/*. ---- -rules: - - path: "auth/oidc/*" - capabilities: - - create - - update - - read - - delete - - list - -auth: - approle: - - tf_vault - k8s/au/syd1: - - woodpecker_terraform_vault diff --git a/policies/identity/group/admin.yaml b/policies/identity/group/admin.yaml deleted file mode 100644 index d077a51..0000000 --- a/policies/identity/group/admin.yaml +++ /dev/null @@ -1,38 +0,0 @@ -# Allow the deployer to manage external identity groups and their aliases, which -# is how OIDC group membership (the ak_groups claim) maps onto Vault policies. -# Both the collection endpoints and the per-id endpoints are needed: create posts -# to identity/group, subsequent reads and updates address identity/group/id/. ---- -rules: - - path: "identity/group" - capabilities: - - create - - update - - path: "identity/group/*" - capabilities: - - create - - update - - read - - delete - - list - - path: "identity/group-alias" - capabilities: - - create - - update - - path: "identity/group-alias/*" - capabilities: - - create - - update - - read - - delete - - list - - path: "identity/lookup/group" - capabilities: - - create - - update - -auth: - approle: - - tf_vault - k8s/au/syd1: - - woodpecker_terraform_vault