Step 2 of the ordered ghp plugin add. policies/ghp/admin.yaml grants the
terraform apply identities (tf_vault approle, woodpecker_terraform_vault k8s
role) create/update on ghp/config and ghp/roles/*; policies/ghp/creds/agent.yaml
grants the agents approle read on ghp/creds/agent.
Must merge + apply BEFORE the engine resources (terraform-vault#121): an approle
token's capabilities are fixed at login, so the deployer needs this policy active
in a prior apply before it can write ghp/config.