From 7d13c0442b18b9ac3e57f330b53c01f692c1a37c Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sun, 30 Aug 2026 21:59:25 +1000 Subject: [PATCH] Grant the vault deployer auth/oidc and identity group management The auth/oidc modules in benvin/auth-oidc write auth/oidc/config, auth/oidc/role/* and external identity groups/aliases. AppRole capabilities are fixed at login, so the deployer must already hold these grants when that apply runs. Add policies/auth/oidc/admin.yaml and policies/identity/group/admin.yaml, split out of #147 per the never-bundle rule. --- policies/auth/oidc/admin.yaml | 19 +++++++++++++++ policies/identity/group/admin.yaml | 38 ++++++++++++++++++++++++++++++ 2 files changed, 57 insertions(+) create mode 100644 policies/auth/oidc/admin.yaml create mode 100644 policies/identity/group/admin.yaml diff --git a/policies/auth/oidc/admin.yaml b/policies/auth/oidc/admin.yaml new file mode 100644 index 0000000..9f04b3b --- /dev/null +++ b/policies/auth/oidc/admin.yaml @@ -0,0 +1,19 @@ +# Allow full administration of the OIDC auth backend (mount config and login +# roles), mirroring policies/auth/ldap/admin.yaml. sys/auth/* already covers +# enabling the mount itself; this covers writing auth/oidc/config and +# auth/oidc/role/*. +--- +rules: + - path: "auth/oidc/*" + capabilities: + - create + - update + - read + - delete + - list + +auth: + approle: + - tf_vault + k8s/au/syd1: + - woodpecker_terraform_vault diff --git a/policies/identity/group/admin.yaml b/policies/identity/group/admin.yaml new file mode 100644 index 0000000..d077a51 --- /dev/null +++ b/policies/identity/group/admin.yaml @@ -0,0 +1,38 @@ +# Allow the deployer to manage external identity groups and their aliases, which +# is how OIDC group membership (the ak_groups claim) maps onto Vault policies. +# Both the collection endpoints and the per-id endpoints are needed: create posts +# to identity/group, subsequent reads and updates address identity/group/id/. +--- +rules: + - path: "identity/group" + capabilities: + - create + - update + - path: "identity/group/*" + capabilities: + - create + - update + - read + - delete + - list + - path: "identity/group-alias" + capabilities: + - create + - update + - path: "identity/group-alias/*" + capabilities: + - create + - update + - read + - delete + - list + - path: "identity/lookup/group" + capabilities: + - create + - update + +auth: + approle: + - tf_vault + k8s/au/syd1: + - woodpecker_terraform_vault