feat: add terraform-incus approle/policy

This commit is contained in:
Ben Vincent 2025-04-07 16:22:41 +10:00
parent 275b640adc
commit 8bc67e1e5b
2 changed files with 18 additions and 0 deletions

View File

@ -0,0 +1,15 @@
resource "vault_approle_auth_backend_role" "terraform_incus" {
role_name = "terraform_incus"
bind_secret_id = false
token_policies = [
"default_access",
"incus",
]
token_ttl = 60
token_max_ttl = 120
token_bound_cidrs = [
"10.10.12.200/32",
"198.18.13.67/32",
"198.18.13.68/32",
]
}

View File

@ -0,0 +1,3 @@
path "kv/data/service/terraform/incus" {
capabilities = ["read"]
}