policies: let terraform-git seed the gitea engine admin credential to KV #102

Merged
benvin merged 1 commits from benvin/gitea-kv-writer into master 2026-07-27 20:22:41 +10:00
Owner

Why

terraform-git now provisions the gitea-vault-admin site-admin bot and writes its generated password to kv/service/vault/au/syd1/secret_backend/gitea/config (as admin_username + admin_password) so the gitea secrets engine can consume it at creation time. The woodpecker_terraform_git / terraform_git identity has no write access to that KV path, so its apply would 403 without this grant.

The deployer that reads the seed already has read access via policies/kv/service/vault/secret_backends_read.yaml (kv/data/service/vault/+/+/secret_backend/*), so only the write side is added here.

Change

  • Add policies/kv/service/vault/au/syd1/secret_backend/gitea/config_write.yaml granting create/read/update on the gitea config KV path to the terraform_git approle and woodpecker_terraform_git k8s role.

Ordering

Merge + apply this before the terraform-git benvin/gitea-vault-admin PR applies (which performs the write). Files are disjoint from the other gitea terraform-vault PRs (#100, #101).

https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv

## Why terraform-git now provisions the `gitea-vault-admin` site-admin bot and writes its generated password to `kv/service/vault/au/syd1/secret_backend/gitea/config` (as `admin_username` + `admin_password`) so the gitea secrets engine can consume it at creation time. The `woodpecker_terraform_git` / `terraform_git` identity has no write access to that KV path, so its apply would 403 without this grant. The deployer that *reads* the seed already has read access via `policies/kv/service/vault/secret_backends_read.yaml` (`kv/data/service/vault/+/+/secret_backend/*`), so only the write side is added here. ## Change - Add `policies/kv/service/vault/au/syd1/secret_backend/gitea/config_write.yaml` granting `create`/`read`/`update` on the gitea config KV path to the `terraform_git` approle and `woodpecker_terraform_git` k8s role. ## Ordering Merge + apply this before the terraform-git `benvin/gitea-vault-admin` PR applies (which performs the write). Files are disjoint from the other gitea terraform-vault PRs (#100, #101). https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
unkinben added 1 commit 2026-07-27 19:29:59 +10:00
policies: let terraform-git seed the gitea engine admin credential to KV
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
9c35b41ab1
Why: terraform-git now provisions the gitea-vault-admin site-admin bot and
writes its generated password to kv/service/vault/au/syd1/secret_backend/gitea/config
so the gitea secrets engine can consume it at creation time. The
woodpecker_terraform_git / terraform_git identity has no write access to that
KV path, so its apply would 403 without this grant. The deployer that reads the
seed already has read via policies/kv/service/vault/secret_backends_read.yaml.

Change:
- Add policies/kv/service/vault/au/syd1/secret_backend/gitea/config_write.yaml
  granting create/read/update on the gitea config KV path to the terraform_git
  approle and woodpecker_terraform_git k8s role.

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
benvin merged commit 2c27395613 into master 2026-07-27 20:22:41 +10:00
benvin deleted branch benvin/gitea-kv-writer 2026-07-27 20:22:41 +10:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/terraform-vault#102