Grant vault deployer access to import + manage the rancher engine #91

Merged
benvin merged 2 commits from benvin/rancher-deployer-policy into master 2026-07-18 14:34:54 +10:00
2 changed files with 64 additions and 0 deletions
+45
View File
@@ -0,0 +1,45 @@
# Allow the vault deployer to manage the rancher secrets engine: its connection
# config, seeded (auto-rotated) service-account tokens, and token-minting roles.
#
# Scoped to rancher/* only. The plugin-catalog grant needed to import the plugin
# lives under policies/sys/plugins/catalog/ so a code owner of this policy path
# cannot grant themselves access outside the rancher mount.
---
rules:
# Engine connection config.
- path: "rancher/config"
capabilities:
- create
- read
- update
- delete
# Seeded, auto-rotated service-account tokens (+ manual rotate).
- path: "rancher/service-accounts/*"
capabilities:
- create
- read
- update
- delete
- list
- path: "rancher/service-accounts"
capabilities:
- read
- list
# Token-minting roles.
- path: "rancher/roles/*"
capabilities:
- create
- read
- update
- delete
- list
- path: "rancher/roles"
capabilities:
- read
- list
auth:
approle:
- tf_vault
k8s/au/syd1:
- woodpecker_terraform_vault
+19
View File
@@ -0,0 +1,19 @@
# Allow the vault deployer to import (register/deregister) the rancher secrets
# plugin in the catalog. sys/plugins/catalog is sudo-protected, so this lives
# under policies/sys/ where only a sys code owner can grant it — keeping the
# rancher engine policy (policies/rancher/) scoped to rancher/* paths.
---
rules:
- path: "sys/plugins/catalog/secret/vault-plugin-secrets-rancher"
capabilities:
- create
- read
- update
- delete
- sudo
auth:
approle:
- tf_vault
k8s/au/syd1:
- woodpecker_terraform_vault