Merge pull request 'feat: add puppetapi approle/policy' (#4) from neoloc/puppetapi into master
Reviewed-on: https://git.query.consul/unkin/terraform-vault/pulls/4
This commit was merged in pull request #4.
This commit is contained in:
@@ -0,0 +1,14 @@
|
||||
resource "vault_approle_auth_backend_role" "puppetapi" {
|
||||
role_name = "puppetapi"
|
||||
bind_secret_id = false
|
||||
token_policies = ["puppetapi_read_tokens"]
|
||||
token_ttl = 30
|
||||
token_max_ttl = 30
|
||||
token_bound_cidrs = [
|
||||
"198.18.17.3/32",
|
||||
"198.18.13.32/32",
|
||||
"198.18.13.33/32",
|
||||
"198.18.13.34/32",
|
||||
"198.18.13.46/32"
|
||||
]
|
||||
}
|
||||
+2
-1
@@ -11,7 +11,8 @@ locals {
|
||||
"policies/rundeck",
|
||||
"policies/ssh-host-signer",
|
||||
"policies/sshca",
|
||||
"policies/kv/service/glauth/services"
|
||||
"policies/kv/service/glauth/services",
|
||||
"policies/kv/service/puppetapi",
|
||||
]
|
||||
}
|
||||
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
path "kv/data/service/puppetapi/tokens" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
Reference in New Issue
Block a user