policies: grant the vault deployer access to the gitea secrets engine #100

Merged
benvin merged 1 commits from benvin/gitea-deployer-access into master 2026-07-27 19:10:22 +10:00

1 Commits

Author SHA1 Message Date
unkinben 724fcf2a76 policies: grant the vault deployer access to the gitea secrets engine
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
Why: applying the forthcoming gitea_secret_backend + role config from
terraform-vault requires the deployment identity (tf_vault approle /
woodpecker_terraform_vault k8s role) to write the engine's config and roles.
Without it, the engine apply 403s. This mirrors policies/rancher/admin.yaml.

Change:
- Add policies/gitea/admin.yaml granting create/read/update/delete on
  gitea/config, create/update on gitea/config/rotate-root, and full manage
  on gitea/roles/*; excludes gitea/creds/* (minting is for consumers).
- Catalog registration is already covered by the shared wildcard grant in
  policies/sys/plugins/catalog/admin.yaml and mounting uses existing
  sys/mounts/* access, so no new catalog/mount grant is added (matches rancher).

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
2026-07-27 19:02:08 +10:00