vault: add arrstack policies (deployer + KV read + creds) (2/3) #126
@@ -0,0 +1,13 @@
|
||||
# config/plugins/vault-plugin-secrets-arrstack.yaml
|
||||
# Imports (registers) the arrstack secrets plugin in the catalog. Filename =
|
||||
# catalog name = mount type. The binary is installed on the OpenBao nodes by
|
||||
# Puppet (openbao-plugin-secrets-arrstack RPM ->
|
||||
# /opt/openbao-plugins/vault-plugin-secrets-arrstack).
|
||||
#
|
||||
# sha256 pins the released v0.1.0 binary; bump it in lockstep with any RPM
|
||||
# upgrade or OpenBao will refuse to launch the plugin. Registration only
|
||||
# succeeds once the Puppet PR has installed the binary on the nodes.
|
||||
type: secret
|
||||
command: vault-plugin-secrets-arrstack
|
||||
version: "0.1.0"
|
||||
sha256: "f8ee60ca7ba14819976acb7dc4cfb6799e3e8da8f871d0bb2bd18d1d9e537972"
|
||||
@@ -0,0 +1,27 @@
|
||||
# Allow management of the arrstack secrets engine (config and roles) by the
|
||||
# terraform-vault deployer.
|
||||
---
|
||||
rules:
|
||||
- path: "arrstack/config"
|
||||
capabilities:
|
||||
- create
|
||||
- update
|
||||
- read
|
||||
- delete
|
||||
- path: "arrstack/roles/*"
|
||||
capabilities:
|
||||
- create
|
||||
- update
|
||||
- delete
|
||||
- read
|
||||
- list
|
||||
- path: "arrstack/roles"
|
||||
capabilities:
|
||||
- read
|
||||
- list
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- tf_vault
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_vault
|
||||
@@ -0,0 +1,12 @@
|
||||
# Allow the terraform-prowlarr run to mint a Prowlarr-scoped arrproxy key.
|
||||
---
|
||||
rules:
|
||||
- path: "arrstack/creds/prowlarr"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- terraform_prowlarr
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_prowlarr
|
||||
@@ -0,0 +1,12 @@
|
||||
# Allow the terraform-radarr run to mint a Radarr-scoped arrproxy key.
|
||||
---
|
||||
rules:
|
||||
- path: "arrstack/creds/radarr"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- terraform_radarr
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_radarr
|
||||
@@ -0,0 +1,12 @@
|
||||
# Allow the terraform-sonarr run to mint a Sonarr-scoped arrproxy key.
|
||||
---
|
||||
rules:
|
||||
- path: "arrstack/creds/sonarr"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- terraform_sonarr
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_sonarr
|
||||
@@ -0,0 +1,22 @@
|
||||
# Allow the terraform-vault deployer to read the seeded arrproxy admin token so
|
||||
# the arrstack engine config module can source it. The token is seeded by
|
||||
# argocd-apps #384 at kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token.
|
||||
# The deployer's existing secret_backends_read policy only covers
|
||||
# kv/data/service/vault/+/+/secret_backend/*, which does not match this
|
||||
# kubernetes/namespace path, so this adds the minimal read grant rather than
|
||||
# duplicating the secret into the litellm-style path. vault_kv_secret_v2 also
|
||||
# reads the kv-v2 metadata path on every plan/apply, so grant that too.
|
||||
---
|
||||
rules:
|
||||
- path: "kv/data/kubernetes/namespace/arrstack/default/arrproxy-admin-token"
|
||||
capabilities:
|
||||
- read
|
||||
- path: "kv/metadata/kubernetes/namespace/arrstack/default/arrproxy-admin-token"
|
||||
capabilities:
|
||||
- read
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- tf_vault
|
||||
k8s/au/syd1:
|
||||
- woodpecker_terraform_vault
|
||||
Reference in New Issue
Block a user