Remove ghp agent role (missing installation_id; unblock apply)
The ghp agent role fails at apply with `installation_id is required for agent tokens` because config/ghp_secret_backend_role/ghp/agent.yaml carries a placeholder installation_id. Remove the role for now so the master apply goes green and does not block the arrstack #127 apply. The ghp backend is retained; re-add the role once a real installation_id is available. - Delete config/ghp_secret_backend_role/ghp/agent.yaml (empties the ghp_secret_backend_role for_each map).
This commit is contained in:
@@ -1,15 +0,0 @@
|
||||
# Role minting ephemeral, scoped ghp agent tokens. Reading ghp/creds/agent mints
|
||||
# a lease-bound token deleted from ghp on revoke/expiry. token_type "agent" binds
|
||||
# the minted token to a ghp App installation, so installation_id is REQUIRED.
|
||||
#
|
||||
# installation_id below is a PLACEHOLDER (0) and MUST be set to the real ghp App
|
||||
# installation id before this role can mint usable tokens. scopes are ghp
|
||||
# permission:level pairs; contents:read is the least-privilege default.
|
||||
---
|
||||
token_type: agent
|
||||
installation_id: 0 # PLACEHOLDER - set to the real ghp App installation id
|
||||
scopes:
|
||||
- contents:read
|
||||
session_prefix: vault
|
||||
ttl: 3600 # 1h
|
||||
max_ttl: 86400 # 24h
|
||||
Reference in New Issue
Block a user