From a962a22416f7c8581f152467c17a7a746115fff8 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sun, 16 Aug 2026 14:44:15 +1000 Subject: [PATCH] vault: add ghp engine config-write + consumer policies (pre-step) Step 2 of the ordered ghp plugin add. policies/ghp/admin.yaml grants the terraform apply identities (tf_vault approle, woodpecker_terraform_vault k8s role) create/update on ghp/config and ghp/roles/*; policies/ghp/creds/agent.yaml grants the agents approle read on ghp/creds/agent. Must merge + apply BEFORE the engine resources (terraform-vault#121): an approle token's capabilities are fixed at login, so the deployer needs this policy active in a prior apply before it can write ghp/config. --- policies/ghp/admin.yaml | 37 +++++++++++++++++++++++++++++++++++ policies/ghp/creds/agent.yaml | 13 ++++++++++++ 2 files changed, 50 insertions(+) create mode 100644 policies/ghp/admin.yaml create mode 100644 policies/ghp/creds/agent.yaml diff --git a/policies/ghp/admin.yaml b/policies/ghp/admin.yaml new file mode 100644 index 0000000..58ea65f --- /dev/null +++ b/policies/ghp/admin.yaml @@ -0,0 +1,37 @@ +# Allow the vault deployer to manage the ghp token secrets engine: its +# connection config (seeded service token) and its token-minting roles. +# +# Scoped to ghp/* only, and deliberately excludes ghp/creds/* - minting tokens +# is for consumers, not the deployer. ghp has NO rotate endpoint, so unlike the +# gitea/netbox engines there is no config/rotate grant here. The plugin-catalog +# grant needed to import the plugin is the shared, sudo-protected wildcard in +# policies/sys/plugins/catalog/admin.yaml (already covers this plugin), and +# mounting the engine uses the deployer's existing sys/mounts/* access, so no +# new catalog/mount grant is added here (mirrors the gitea/netbox engines). +--- +rules: + # Engine connection config (base_url, TLS, seeded service token). + - path: "ghp/config" + capabilities: + - create + - read + - update + - delete + # Token-minting roles. + - path: "ghp/roles/*" + capabilities: + - create + - read + - update + - delete + - list + - path: "ghp/roles" + capabilities: + - read + - list + +auth: + approle: + - tf_vault + k8s/au/syd1: + - woodpecker_terraform_vault diff --git a/policies/ghp/creds/agent.yaml b/policies/ghp/creds/agent.yaml new file mode 100644 index 0000000..fb99925 --- /dev/null +++ b/policies/ghp/creds/agent.yaml @@ -0,0 +1,13 @@ +# Lets the agents AppRole mint ephemeral ghp agent tokens, so AI coding agents +# authenticate to ghp as their own short-lived, least-privilege identity. +# Reading ghp/creds/agent returns a lease-bound token scoped by the role +# (token_type agent, contents:read). Mirrors the gitea/creds/unkin-agent binding. +--- +rules: + - path: "ghp/creds/agent" + capabilities: + - read + +auth: + approle: + - agents -- 2.47.3