Merge branch 'master' into benvin/grant-agents-ghp-config-write
This commit is contained in:
@@ -1,15 +0,0 @@
|
||||
# Mounts the ghp token secrets engine at "ghp" and writes its config.
|
||||
# The seeded ghp service token is sensitive and read from KV, not stored here:
|
||||
# kv/service/vault/au/syd1/secret_backend/ghp/config
|
||||
# -> key: admin_token (required) the shared ghpsvc_... service token
|
||||
#
|
||||
# admin_token is a static shared secret provisioned into KV by an operator. The
|
||||
# SAME token value must also be present in the running ghp deployment's accepted
|
||||
# service tokens (GHP_AUTH_SERVICE_TOKENS) so ghp ACCEPTS what this engine
|
||||
# PRESENTS. ghp has no rotate endpoint, so the engine never rotates it in place;
|
||||
# the mount uses ignore_changes=[admin_token], making the KV seed create-only
|
||||
# (re-reading a stale KV value never re-pushes it to a live mount).
|
||||
description: "ghp ephemeral scoped agent token engine"
|
||||
base_url: "https://ghp.unkin.net"
|
||||
tls_skip_verify: false
|
||||
request_timeout_seconds: 30
|
||||
@@ -1,15 +0,0 @@
|
||||
# Role minting ephemeral, scoped ghp agent tokens. Reading ghp/creds/agent mints
|
||||
# a lease-bound token deleted from ghp on revoke/expiry. token_type "agent" binds
|
||||
# the minted token to a ghp App installation, so installation_id is REQUIRED.
|
||||
#
|
||||
# installation_id below is a PLACEHOLDER (0) and MUST be set to the real ghp App
|
||||
# installation id before this role can mint usable tokens. scopes are ghp
|
||||
# permission:level pairs; contents:read is the least-privilege default.
|
||||
---
|
||||
token_type: agent
|
||||
installation_id: 0 # PLACEHOLDER - set to the real ghp App installation id
|
||||
scopes:
|
||||
- contents:read
|
||||
session_prefix: vault
|
||||
ttl: 3600 # 1h
|
||||
max_ttl: 86400 # 24h
|
||||
@@ -0,0 +1,27 @@
|
||||
# Allow management of the arrstack secrets engine (config and roles) by the
|
||||
# terraform-vault deployer.
|
||||
---
|
||||
rules:
|
||||
- path: "arrstack/config"
|
||||
capabilities:
|
||||
- create
|
||||
- update
|
||||
- read
|
||||
- delete
|
||||
- path: "arrstack/roles/*"
|
||||
capabilities:
|
||||
- create
|
||||
- update
|
||||
- delete
|
||||
- read
|
||||
- list
|
||||
- path: "arrstack/roles"
|
||||
capabilities:
|
||||
- read
|
||||
- list
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- tf_vault
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_vault
|
||||
@@ -0,0 +1,12 @@
|
||||
# Allow the terraform-prowlarr run to mint a Prowlarr-scoped arrproxy key.
|
||||
---
|
||||
rules:
|
||||
- path: "arrstack/creds/prowlarr"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- terraform_prowlarr
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_prowlarr
|
||||
@@ -0,0 +1,12 @@
|
||||
# Allow the terraform-radarr run to mint a Radarr-scoped arrproxy key.
|
||||
---
|
||||
rules:
|
||||
- path: "arrstack/creds/radarr"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- terraform_radarr
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_radarr
|
||||
@@ -0,0 +1,12 @@
|
||||
# Allow the terraform-sonarr run to mint a Sonarr-scoped arrproxy key.
|
||||
---
|
||||
rules:
|
||||
- path: "arrstack/creds/sonarr"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- terraform_sonarr
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_sonarr
|
||||
@@ -0,0 +1,22 @@
|
||||
# Allow the terraform-vault deployer to read the seeded arrproxy admin token so
|
||||
# the arrstack engine config module can source it. The token is seeded by
|
||||
# argocd-apps #384 at kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token.
|
||||
# The deployer's existing secret_backends_read policy only covers
|
||||
# kv/data/service/vault/+/+/secret_backend/*, which does not match this
|
||||
# kubernetes/namespace path, so this adds the minimal read grant rather than
|
||||
# duplicating the secret into the litellm-style path. vault_kv_secret_v2 also
|
||||
# reads the kv-v2 metadata path on every plan/apply, so grant that too.
|
||||
---
|
||||
rules:
|
||||
- path: "kv/data/kubernetes/namespace/arrstack/default/arrproxy-admin-token"
|
||||
capabilities:
|
||||
- read
|
||||
- path: "kv/metadata/kubernetes/namespace/arrstack/default/arrproxy-admin-token"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- tf_vault
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_vault
|
||||
Reference in New Issue
Block a user