Grant the terraform-ipam Woodpecker pipeline the same Vault footprint as the
other terraform-* runners, plus a KV read for its provider tokens:
- k8s auth role woodpecker_terraform_ipam (SA terraform-ipam / woodpecker ns)
- consul secret backend role + ACL policy writing infra/terraform/ipam/*
- consul creds read policy
- kv read policy for kv/service/terraform/ipam (netbox_token + kea_token)
Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT