7814551084
feat: manage k8s auth role integration
...
- add policies to sign/issue certificates
- manage auth roles for ceph-csi, certmanager, externaldns, huntarr
2025-11-22 23:21:43 +11:00
5cbd5815a0
chore: format policy files
...
- ensure all policy files are correctly formatted
2025-11-16 13:35:10 +11:00
cbee19b5f9
feat: move k8s secrets into vault
...
- update kubernetes_host to match value in jwt
- regenerate jwt token and store in vault
- add policy to enable access to jwt token
- update tf_deploy user with access to token
2025-11-16 12:42:18 +11:00
d508dcd4a9
feat: enable access to puppetcerts
...
- enable the terraform-incus repo to access puppet certs
2025-04-27 16:26:05 +10:00
05268f9dd8
feat: enable access to kv/service/packer/builder/docker-incus-client
2025-04-23 18:24:36 +10:00
8bc67e1e5b
feat: add terraform-incus approle/policy
2025-04-07 16:22:41 +10:00
275b640adc
feat: add packer-builder policy
2025-04-07 16:22:22 +10:00
2d345cc63b
fix: fix rolename
...
- had duplicate role
- change policy name to match approle
- updated ttl as packer builds can take some time
2025-01-11 21:32:33 +11:00
f83ba13158
feat: add packer-builder role
...
- limit access to workstation and gitea runners
2025-01-11 21:01:17 +11:00
12e04b3db7
feat: add incus-cluster role/policies
...
- add policy and role to manage incus cluster join tokens
2025-01-06 23:16:06 +11:00
fc22ac1711
feat: add terraform_nomad role
...
- add approle and policy for nomad terraform
2024-12-28 17:14:14 +11:00
63dd355311
feat: add puppetapi approle/policy
2024-12-15 17:07:01 +11:00
f78416361b
feat: manage terraform access to vault
...
- add approle for terraform, tf_vault
- add policices to manage terraform access to vault
- add policices for default access to vault from ldap users
2024-09-26 22:59:40 +10:00