policies: grant the vault deployer access to the gitea secrets engine #100

Merged
benvin merged 1 commits from benvin/gitea-deployer-access into master 2026-07-27 19:10:22 +10:00
Owner

Why

The forthcoming gitea_secret_backend + role configuration (separate PR, benvin/gitea-secret-engine) is applied by terraform-vault under the deployment identity (tf_vault approle / woodpecker_terraform_vault k8s role). That identity has no access to the gitea/ mount yet, so writing the engine's config and roles would 403. This mirrors policies/rancher/admin.yaml.

Change

  • Add policies/gitea/admin.yaml granting the deployer:
    • create/read/update/delete on gitea/config
    • create/update on gitea/config/rotate-root (write-only rotation trigger)
    • full manage + list on gitea/roles/* (and list on gitea/roles)
  • Deliberately excludes gitea/creds/* — minting tokens is for consumers, not the deployer.
  • No new catalog or mount grant: plugin registration is already covered by the shared, sudo-protected wildcard in policies/sys/plugins/catalog/admin.yaml, and mounting uses the deployer's existing sys/mounts/* access — same as the rancher engine.

Order

Merge and apply this before the benvin/gitea-secret-engine PR, so the deployer can write the engine config/roles on that apply.

https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv

## Why The forthcoming `gitea_secret_backend` + role configuration (separate PR, `benvin/gitea-secret-engine`) is applied by terraform-vault under the deployment identity (`tf_vault` approle / `woodpecker_terraform_vault` k8s role). That identity has no access to the `gitea/` mount yet, so writing the engine's config and roles would 403. This mirrors `policies/rancher/admin.yaml`. ## Change - Add `policies/gitea/admin.yaml` granting the deployer: - create/read/update/delete on `gitea/config` - create/update on `gitea/config/rotate-root` (write-only rotation trigger) - full manage + list on `gitea/roles/*` (and list on `gitea/roles`) - Deliberately excludes `gitea/creds/*` — minting tokens is for consumers, not the deployer. - No new catalog or mount grant: plugin registration is already covered by the shared, sudo-protected wildcard in `policies/sys/plugins/catalog/admin.yaml`, and mounting uses the deployer's existing `sys/mounts/*` access — same as the rancher engine. ## Order Merge and apply this **before** the `benvin/gitea-secret-engine` PR, so the deployer can write the engine config/roles on that apply. https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
unkinben added 1 commit 2026-07-27 19:02:30 +10:00
policies: grant the vault deployer access to the gitea secrets engine
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
724fcf2a76
Why: applying the forthcoming gitea_secret_backend + role config from
terraform-vault requires the deployment identity (tf_vault approle /
woodpecker_terraform_vault k8s role) to write the engine's config and roles.
Without it, the engine apply 403s. This mirrors policies/rancher/admin.yaml.

Change:
- Add policies/gitea/admin.yaml granting create/read/update/delete on
  gitea/config, create/update on gitea/config/rotate-root, and full manage
  on gitea/roles/*; excludes gitea/creds/* (minting is for consumers).
- Catalog registration is already covered by the shared wildcard grant in
  policies/sys/plugins/catalog/admin.yaml and mounting uses existing
  sys/mounts/* access, so no new catalog/mount grant is added (matches rancher).

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
benvin merged commit d289775e38 into master 2026-07-27 19:10:22 +10:00
benvin deleted branch benvin/gitea-deployer-access 2026-07-27 19:10:22 +10:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/terraform-vault#100