Grant the agents approle read+write on the woodpecker agent token #151
@@ -0,0 +1,21 @@
|
||||
# Lets the agents AppRole read and maintain a dedicated Woodpecker API token.
|
||||
# Agents query the Woodpecker API to inspect pipeline runs and failing steps when
|
||||
# reviewing PRs; today that token is pasted into agent config by hand. Granting
|
||||
# create/update as well as read lets automation seed and rotate it in place,
|
||||
# mirroring the agents-approle grant on kv/kubernetes/*. delete is excluded, as
|
||||
# it is there.
|
||||
---
|
||||
rules:
|
||||
- path: "kv/data/service/woodpecker/tokens/agents"
|
||||
capabilities:
|
||||
- create
|
||||
- read
|
||||
- update
|
||||
- path: "kv/metadata/service/woodpecker/tokens/agents"
|
||||
capabilities:
|
||||
- read
|
||||
- list
|
||||
|
||||
auth:
|
||||
approle:
|
||||
- agents
|
||||
Reference in New Issue
Block a user