Why: applying the forthcoming gitea_secret_backend + role config from
terraform-vault requires the deployment identity (tf_vault approle /
woodpecker_terraform_vault k8s role) to write the engine's config and roles.
Without it, the engine apply 403s. This mirrors policies/rancher/admin.yaml.
Change:
- Add policies/gitea/admin.yaml granting create/read/update/delete on
gitea/config, create/update on gitea/config/rotate-root, and full manage
on gitea/roles/*; excludes gitea/creds/* (minting is for consumers).
- Catalog registration is already covered by the shared wildcard grant in
policies/sys/plugins/catalog/admin.yaml and mounting uses existing
sys/mounts/* access, so no new catalog/mount grant is added (matches rancher).
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv