- had duplicate role - change policy name to match approle
- limit access to workstation and gitea runners