1 Commits

Author SHA1 Message Date
unkin-agent dc18f2e556 Add logging/vlogs kubernetes auth role
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
Bind the templated kv/kubernetes policy to it
2026-09-28 22:37:24 +10:00
3 changed files with 22 additions and 0 deletions
@@ -0,0 +1,7 @@
bound_service_account_names:
- vlogs
bound_service_account_namespaces:
- logging
token_ttl: 600
token_max_ttl: 600
audience: vault
+1
View File
@@ -14,3 +14,4 @@ rules:
auth:
k8s/au/syd1:
- default
- logging_vlogs
@@ -0,0 +1,14 @@
# Allow the Terraform Authentik runner to read the vlogs OIDC client secret. It is
# a second OIDC client in an already-onboarded namespace, so it cannot use the
# one-per-namespace oauth-credentials path.
---
rules:
- path: "kv/data/kubernetes/namespace/logging/default/vlogs-oauth-credentials"
capabilities:
- read
auth:
approle:
- terraform_authentik
k8s/au/syd1:
- woodpecker_terraform_authentik