From 594f67f5259579f38f433ed7fb30c18809f51c9b Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sun, 30 Aug 2026 21:22:12 +1000 Subject: [PATCH] Grant the vault deployer read on the Authentik OIDC client secret Authentik's provider module generates the OpenBao OIDC client and writes its credentials to kv/service/authentik/oidc-vault (terraform_authentik owns that subtree). The terraform-vault deployer needs to read them to configure the auth/oidc backend, and AppRole capabilities are fixed at login, so the grant must land in a prior apply. Add policies/kv/service/authentik/oidc-vault/read.yaml granting read on kv/data/service/authentik/oidc-vault to the deployer identities (approle tf_vault and k8s/au/syd1 woodpecker_terraform_vault). --- .../kv/service/authentik/oidc-vault/read.yaml | 21 +++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 policies/kv/service/authentik/oidc-vault/read.yaml diff --git a/policies/kv/service/authentik/oidc-vault/read.yaml b/policies/kv/service/authentik/oidc-vault/read.yaml new file mode 100644 index 0000000..df475d4 --- /dev/null +++ b/policies/kv/service/authentik/oidc-vault/read.yaml @@ -0,0 +1,21 @@ +# Let the terraform-vault deployer read the OpenBao OIDC client credentials that +# Authentik's provider module generates and writes here (terraform_authentik owns +# kv/service/authentik/* — see policies/kv/service/authentik/write.yaml). The +# deployer consumes client_id/client_secret to configure the auth/oidc backend. +# +# OIDC becomes the default human auth path; approle and k8s (CI and agents) plus +# the break-glass root path are unchanged. +# +# AppRole capabilities are fixed at login, so this grant must be applied before +# the PR that adds the auth/oidc modules. +--- +rules: + - path: "kv/data/service/authentik/oidc-vault" + capabilities: + - read + +auth: + approle: + - tf_vault + k8s/au/syd1: + - woodpecker_terraform_vault -- 2.47.3