2 Commits

Author SHA1 Message Date
unkinben 2c27395613 policies: let terraform-git seed the gitea engine admin credential to KV (#102)
ci/woodpecker/push/apply Pipeline was successful
## Why

terraform-git now provisions the `gitea-vault-admin` site-admin bot and writes its generated password to `kv/service/vault/au/syd1/secret_backend/gitea/config` (as `admin_username` + `admin_password`) so the gitea secrets engine can consume it at creation time. The `woodpecker_terraform_git` / `terraform_git` identity has no write access to that KV path, so its apply would 403 without this grant.

The deployer that *reads* the seed already has read access via `policies/kv/service/vault/secret_backends_read.yaml` (`kv/data/service/vault/+/+/secret_backend/*`), so only the write side is added here.

## Change

- Add `policies/kv/service/vault/au/syd1/secret_backend/gitea/config_write.yaml` granting `create`/`read`/`update` on the gitea config KV path to the `terraform_git` approle and `woodpecker_terraform_git` k8s role.

## Ordering

Merge + apply this before the terraform-git `benvin/gitea-vault-admin` PR applies (which performs the write). Files are disjoint from the other gitea terraform-vault PRs (#100, #101).

https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
Reviewed-on: #102
Co-authored-by: Ben Vincent <ben@unkin.net>
Co-committed-by: Ben Vincent <ben@unkin.net>
2026-07-27 20:22:40 +10:00
unkinben d289775e38 policies: grant the vault deployer access to the gitea secrets engine (#100)
ci/woodpecker/push/apply Pipeline was successful
## Why

The forthcoming `gitea_secret_backend` + role configuration (separate PR, `benvin/gitea-secret-engine`) is applied by terraform-vault under the deployment identity (`tf_vault` approle / `woodpecker_terraform_vault` k8s role). That identity has no access to the `gitea/` mount yet, so writing the engine's config and roles would 403. This mirrors `policies/rancher/admin.yaml`.

## Change

- Add `policies/gitea/admin.yaml` granting the deployer:
  - create/read/update/delete on `gitea/config`
  - create/update on `gitea/config/rotate-root` (write-only rotation trigger)
  - full manage + list on `gitea/roles/*` (and list on `gitea/roles`)
- Deliberately excludes `gitea/creds/*` — minting tokens is for consumers, not the deployer.
- No new catalog or mount grant: plugin registration is already covered by the shared, sudo-protected wildcard in `policies/sys/plugins/catalog/admin.yaml`, and mounting uses the deployer's existing `sys/mounts/*` access — same as the rancher engine.

## Order

Merge and apply this **before** the `benvin/gitea-secret-engine` PR, so the deployer can write the engine config/roles on that apply.

https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
Reviewed-on: #100
Co-authored-by: Ben Vincent <ben@unkin.net>
Co-committed-by: Ben Vincent <ben@unkin.net>
2026-07-27 19:10:21 +10:00
2 changed files with 62 additions and 0 deletions
+42
View File
@@ -0,0 +1,42 @@
# Allow the vault deployer to manage the gitea token secrets engine: its
# connection config (seeded admin credentials), in-place root rotation, and
# token-minting roles.
#
# Scoped to gitea/* only, and deliberately excludes gitea/creds/* — minting
# tokens is for consumers, not the deployer. The plugin-catalog grant needed to
# import the plugin is the shared, sudo-protected wildcard in
# policies/sys/plugins/catalog/admin.yaml (already covers this plugin), and
# mounting the engine uses the deployer's existing sys/mounts/* access, so no
# new catalog/mount grant is added here (mirrors the rancher engine).
---
rules:
# Engine connection config (Gitea URL, TLS, seeded admin username/password).
- path: "gitea/config"
capabilities:
- create
- read
- update
- delete
# In-place rotation of the seeded admin password (write-only trigger).
- path: "gitea/config/rotate-root"
capabilities:
- create
- update
# Token-minting roles.
- path: "gitea/roles/*"
capabilities:
- create
- read
- update
- delete
- list
- path: "gitea/roles"
capabilities:
- read
- list
auth:
approle:
- tf_vault
k8s/au/syd1:
- woodpecker_terraform_vault
@@ -0,0 +1,20 @@
# Allow terraform-git to seed (write once) the gitea secrets engine's admin
# credentials. terraform-git creates the gitea-vault-admin site-admin bot and
# writes its generated password here as admin_username + admin_password; the
# vault gitea engine (managed by the tf_vault deployer) reads it at gitea/config
# creation time. Read is already granted to the deployer via
# policies/kv/service/vault/secret_backends_read.yaml, so this only adds the
# write side for terraform-git's own identity.
---
rules:
- path: "kv/data/service/vault/au/syd1/secret_backend/gitea/config"
capabilities:
- create
- read
- update
auth:
approle:
- terraform_git
k8s/au/syd1:
- woodpecker_terraform_git