feat: enable access to puppetcerts

- enable the terraform-incus repo to access puppet certs
This commit is contained in:
Ben Vincent 2025-04-27 16:24:24 +10:00
parent 4aac926c6a
commit d508dcd4a9
3 changed files with 8 additions and 0 deletions

View File

@ -4,6 +4,7 @@ resource "vault_approle_auth_backend_role" "terraform_incus" {
token_policies = [
"default_access",
"incus",
"terraform_puppet_cert",
]
token_ttl = 60
token_max_ttl = 120

View File

@ -15,6 +15,7 @@ locals {
"policies/kv/service/glauth/services",
"policies/kv/service/incus",
"policies/kv/service/packer",
"policies/kv/service/puppet/certificates",
"policies/kv/service/puppetapi",
"policies/kv/service/terraform",
]

View File

@ -0,0 +1,6 @@
path "kv/data/service/puppet/certificates/terraform" {
capabilities = ["read"]
}
path "kv/data/service/puppet/certificates/ca" {
capabilities = ["read"]
}