1 Commits

Author SHA1 Message Date
unkin-agent 096d677129 Remove the vlogs one-off oauth-credentials policy (#160)
ci/woodpecker/push/apply Pipeline was successful
The vlogs OIDC client secret moves to its own Kubernetes namespace under service account `default`, so it lands on `kv/data/kubernetes/namespace/vlogs/default/oauth-credentials`. The shared per-namespace rule already matches that path, leaving the vlogs-specific policy with nothing to grant.

- Delete `policies/kv/kubernetes/namespace/logging/default/vlogs-oauth-credentials/read.yaml`.

The shared oauth-credentials policy is untouched.

Reviewed-on: #160
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-28 22:47:51 +10:00
@@ -1,14 +0,0 @@
# Allow the Terraform Authentik runner to read the vlogs OIDC client secret. It is
# a second OIDC client in an already-onboarded namespace, so it cannot use the
# one-per-namespace oauth-credentials path.
---
rules:
- path: "kv/data/kubernetes/namespace/logging/default/vlogs-oauth-credentials"
capabilities:
- read
auth:
approle:
- terraform_authentik
k8s/au/syd1:
- woodpecker_terraform_authentik