The new terragrunt-enc repo manages all encapi ENC data via Terraform and
needs its own Vault/Consul plumbing, mirroring terraform-git/terraform-incus:
CI auth, isolated consul state, and read access to the ENCAPI_WRITE_TOKEN.
- Add approle role terraform_enc and k8s auth role woodpecker_terraform_enc
(bound to the terraform-enc SA in the woodpecker namespace).
- Add consul secret backend role + ACL rules granting write on
infra/terraform/enc/ for its terragrunt state, plus a policy letting both
auth roles read consul_root/au/syd1/creds/terraform-enc.
- Grant both auth roles read on
kv/data/kubernetes/namespace/encapi/default/environment (ENCAPI_WRITE_TOKEN).