Grant the agents approle read+write on the woodpecker agent token (#151)
ci/woodpecker/push/apply Pipeline was successful
ci/woodpecker/push/apply Pipeline was successful
Agents query the Woodpecker API to inspect pipeline runs and failing steps while reviewing PRs. That token is currently pasted into agent config by hand, so it lives in plaintext on disk instead of in Vault. - add `policies/kv/service/woodpecker/tokens/agents.yaml` - grant the `agents` approle create/read/update on `kv/data/service/woodpecker/tokens/agents` - grant read/list on the matching metadata path; no delete, mirroring the `kv/kubernetes/*` grant Token seeding follows once this is applied. Reviewed-on: #151 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #151.
This commit is contained in:
@@ -0,0 +1,21 @@
|
||||
# Lets the agents AppRole read and maintain a dedicated Woodpecker API token.
|
||||
# Agents query the Woodpecker API to inspect pipeline runs and failing steps when
|
||||
# reviewing PRs; today that token is pasted into agent config by hand. Granting
|
||||
# create/update as well as read lets automation seed and rotate it in place,
|
||||
# mirroring the agents-approle grant on kv/kubernetes/*. delete is excluded, as
|
||||
# it is there.
|
||||
---
|
||||
rules:
|
||||
- path: "kv/data/service/woodpecker/tokens/agents"
|
||||
capabilities:
|
||||
- create
|
||||
- read
|
||||
- update
|
||||
- path: "kv/metadata/service/woodpecker/tokens/agents"
|
||||
capabilities:
|
||||
- read
|
||||
- list
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- agents
|
||||
Reference in New Issue
Block a user