feat: enable access to puppetcerts
- enable the terraform-incus repo to access puppet certs
This commit is contained in:
parent
4aac926c6a
commit
d508dcd4a9
@ -4,6 +4,7 @@ resource "vault_approle_auth_backend_role" "terraform_incus" {
|
|||||||
token_policies = [
|
token_policies = [
|
||||||
"default_access",
|
"default_access",
|
||||||
"incus",
|
"incus",
|
||||||
|
"terraform_puppet_cert",
|
||||||
]
|
]
|
||||||
token_ttl = 60
|
token_ttl = 60
|
||||||
token_max_ttl = 120
|
token_max_ttl = 120
|
||||||
|
|||||||
@ -15,6 +15,7 @@ locals {
|
|||||||
"policies/kv/service/glauth/services",
|
"policies/kv/service/glauth/services",
|
||||||
"policies/kv/service/incus",
|
"policies/kv/service/incus",
|
||||||
"policies/kv/service/packer",
|
"policies/kv/service/packer",
|
||||||
|
"policies/kv/service/puppet/certificates",
|
||||||
"policies/kv/service/puppetapi",
|
"policies/kv/service/puppetapi",
|
||||||
"policies/kv/service/terraform",
|
"policies/kv/service/terraform",
|
||||||
]
|
]
|
||||||
|
|||||||
@ -0,0 +1,6 @@
|
|||||||
|
path "kv/data/service/puppet/certificates/terraform" {
|
||||||
|
capabilities = ["read"]
|
||||||
|
}
|
||||||
|
path "kv/data/service/puppet/certificates/ca" {
|
||||||
|
capabilities = ["read"]
|
||||||
|
}
|
||||||
Loading…
Reference in New Issue
Block a user