Grant the agents approle read+write on the woodpecker agent token (#151)
ci/woodpecker/push/apply Pipeline was successful

Agents query the Woodpecker API to inspect pipeline runs and failing steps while reviewing PRs. That token is currently pasted into agent config by hand, so it lives in plaintext on disk instead of in Vault.

- add `policies/kv/service/woodpecker/tokens/agents.yaml`
- grant the `agents` approle create/read/update on `kv/data/service/woodpecker/tokens/agents`
- grant read/list on the matching metadata path; no delete, mirroring the `kv/kubernetes/*` grant

Token seeding follows once this is applied.

Reviewed-on: #151
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #151.
This commit is contained in:
2026-09-12 13:19:56 +10:00
committed by BenVincent
parent 94e8ac1b2a
commit 9e18627567
@@ -0,0 +1,21 @@
# Lets the agents AppRole read and maintain a dedicated Woodpecker API token.
# Agents query the Woodpecker API to inspect pipeline runs and failing steps when
# reviewing PRs; today that token is pasted into agent config by hand. Granting
# create/update as well as read lets automation seed and rotate it in place,
# mirroring the agents-approle grant on kv/kubernetes/*. delete is excluded, as
# it is there.
---
rules:
- path: "kv/data/service/woodpecker/tokens/agents"
capabilities:
- create
- read
- update
- path: "kv/metadata/service/woodpecker/tokens/agents"
capabilities:
- read
- list
auth:
approle:
- agents