diff --git a/policies/kv/service/woodpecker/tokens/agents.yaml b/policies/kv/service/woodpecker/tokens/agents.yaml new file mode 100644 index 0000000..f083f8c --- /dev/null +++ b/policies/kv/service/woodpecker/tokens/agents.yaml @@ -0,0 +1,21 @@ +# Lets the agents AppRole read and maintain a dedicated Woodpecker API token. +# Agents query the Woodpecker API to inspect pipeline runs and failing steps when +# reviewing PRs; today that token is pasted into agent config by hand. Granting +# create/update as well as read lets automation seed and rotate it in place, +# mirroring the agents-approle grant on kv/kubernetes/*. delete is excluded, as +# it is there. +--- +rules: + - path: "kv/data/service/woodpecker/tokens/agents" + capabilities: + - create + - read + - update + - path: "kv/metadata/service/woodpecker/tokens/agents" + capabilities: + - read + - list + +auth: + approle: + - agents