From bf9c7852819cc7a2d1fda99971fe3839e99c035f Mon Sep 17 00:00:00 2001 From: Ben Vincent Date: Mon, 27 Jul 2026 23:36:53 +1000 Subject: [PATCH] policies: allow terraform-git to delete the gitea config seed for taint recovery (#104) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit terraform-git's apply (pipeline 108) still fails: pipeline 107 actually wrote the seed but the post-create metadata read 403'd, so terraform tainted the resource — recovery is replace (delete+create), and delete was deliberately not granted. Withholding delete doesn't provide the write-once property anyway (that's lifecycle ignore_changes in terraform-git); it just breaks taint recovery and destroy. - add delete on the kv data path for the gitea config seed - add delete on the matching kv metadata path (full destroy support) After merge+apply, restart the terraform-git apply once more — it will replace the tainted seed and go green, unblocking #101. Reviewed-on: https://git.unkin.net/unkin/terraform-vault/pulls/104 Co-authored-by: Ben Vincent Co-committed-by: Ben Vincent --- .../vault/au/syd1/secret_backend/gitea/config_write.yaml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/policies/kv/service/vault/au/syd1/secret_backend/gitea/config_write.yaml b/policies/kv/service/vault/au/syd1/secret_backend/gitea/config_write.yaml index d325a0b..973e4d6 100644 --- a/policies/kv/service/vault/au/syd1/secret_backend/gitea/config_write.yaml +++ b/policies/kv/service/vault/au/syd1/secret_backend/gitea/config_write.yaml @@ -7,16 +7,22 @@ # write side for terraform-git's own identity. --- rules: + # delete is required for taint recovery and destroy (the resource got tainted + # by pipeline 107's failed post-create read and replace = delete+create). + # The seed's write-once semantics are enforced by lifecycle ignore_changes in + # terraform-git, not by withholding delete here. - path: "kv/data/service/vault/au/syd1/secret_backend/gitea/config" capabilities: - create - read - update + - delete # vault_kv_secret_v2 also reads the kv-v2 metadata path on every plan/apply # (403 here broke the terraform-git main apply, pipeline 107). - path: "kv/metadata/service/vault/au/syd1/secret_backend/gitea/config" capabilities: - read + - delete auth: approle: