From 67e79e72dcb3895516f288c216d5b8959a49d4af Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sun, 30 Aug 2026 21:50:57 +1000 Subject: [PATCH 1/2] Grant the vault deployer read on the Authentik OIDC client secret (#146) **Why:** the terraform-vault deployer must read the OpenBao OIDC client credentials that Authentik's provider module generates before it can configure `auth/oidc`, and AppRole capabilities are fixed at login so the grant has to exist in a prior apply. **How:** - Add `policies/kv/service/authentik/oidc-vault/read.yaml`: read on `kv/data/service/authentik/oidc-vault` for the deployer identities (approle `tf_vault`, k8s/au/syd1 `woodpecker_terraform_vault`); `terraform_authentik` still owns the write side of `kv/service/authentik/*`. **Merge order:** this PR must merge and apply *before* the follow-up PR that adds the `auth/oidc` modules. OIDC becomes the default human auth path; approle/k8s (CI and agents) and break-glass are unchanged. Reviewed-on: https://git.unkin.net/unkin/terraform-vault/pulls/146 Co-authored-by: unkin-agent Co-committed-by: unkin-agent --- .../kv/service/authentik/oidc-vault/read.yaml | 21 +++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 policies/kv/service/authentik/oidc-vault/read.yaml diff --git a/policies/kv/service/authentik/oidc-vault/read.yaml b/policies/kv/service/authentik/oidc-vault/read.yaml new file mode 100644 index 0000000..df475d4 --- /dev/null +++ b/policies/kv/service/authentik/oidc-vault/read.yaml @@ -0,0 +1,21 @@ +# Let the terraform-vault deployer read the OpenBao OIDC client credentials that +# Authentik's provider module generates and writes here (terraform_authentik owns +# kv/service/authentik/* — see policies/kv/service/authentik/write.yaml). The +# deployer consumes client_id/client_secret to configure the auth/oidc backend. +# +# OIDC becomes the default human auth path; approle and k8s (CI and agents) plus +# the break-glass root path are unchanged. +# +# AppRole capabilities are fixed at login, so this grant must be applied before +# the PR that adds the auth/oidc modules. +--- +rules: + - path: "kv/data/service/authentik/oidc-vault" + capabilities: + - read + +auth: + approle: + - tf_vault + k8s/au/syd1: + - woodpecker_terraform_vault From a3a8854a164e74042294410deaa528f745938ae9 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sun, 30 Aug 2026 22:14:41 +1000 Subject: [PATCH 2/2] Grant the vault deployer auth/oidc and identity group capabilities (#148) ## Why AppRole capabilities are fixed at login, so the deployer needs `auth/oidc/*` and identity-group grants in an apply that precedes the one creating those resources. ## How - Add `policies/auth/oidc/admin.yaml`: full `auth/oidc/*` administration (mount config and login roles), mirroring `policies/auth/ldap/admin.yaml`. - Add `policies/identity/group/admin.yaml`: manage external identity groups, group aliases and `identity/lookup/group`, on both the collection and per-id endpoints. - Grant both policies to the `tf_vault` approle and the `woodpecker_terraform_vault` k8s role. Apply before #147. Reviewed-on: https://git.unkin.net/unkin/terraform-vault/pulls/148 Co-authored-by: unkin-agent Co-committed-by: unkin-agent --- policies/auth/oidc/admin.yaml | 19 +++++++++++++++ policies/identity/group/admin.yaml | 38 ++++++++++++++++++++++++++++++ 2 files changed, 57 insertions(+) create mode 100644 policies/auth/oidc/admin.yaml create mode 100644 policies/identity/group/admin.yaml diff --git a/policies/auth/oidc/admin.yaml b/policies/auth/oidc/admin.yaml new file mode 100644 index 0000000..9f04b3b --- /dev/null +++ b/policies/auth/oidc/admin.yaml @@ -0,0 +1,19 @@ +# Allow full administration of the OIDC auth backend (mount config and login +# roles), mirroring policies/auth/ldap/admin.yaml. sys/auth/* already covers +# enabling the mount itself; this covers writing auth/oidc/config and +# auth/oidc/role/*. +--- +rules: + - path: "auth/oidc/*" + capabilities: + - create + - update + - read + - delete + - list + +auth: + approle: + - tf_vault + k8s/au/syd1: + - woodpecker_terraform_vault diff --git a/policies/identity/group/admin.yaml b/policies/identity/group/admin.yaml new file mode 100644 index 0000000..d077a51 --- /dev/null +++ b/policies/identity/group/admin.yaml @@ -0,0 +1,38 @@ +# Allow the deployer to manage external identity groups and their aliases, which +# is how OIDC group membership (the ak_groups claim) maps onto Vault policies. +# Both the collection endpoints and the per-id endpoints are needed: create posts +# to identity/group, subsequent reads and updates address identity/group/id/. +--- +rules: + - path: "identity/group" + capabilities: + - create + - update + - path: "identity/group/*" + capabilities: + - create + - update + - read + - delete + - list + - path: "identity/group-alias" + capabilities: + - create + - update + - path: "identity/group-alias/*" + capabilities: + - create + - update + - read + - delete + - list + - path: "identity/lookup/group" + capabilities: + - create + - update + +auth: + approle: + - tf_vault + k8s/au/syd1: + - woodpecker_terraform_vault