# Allow the Terraform Incus runner to read the encapi environment secret # (ENCAPI_WRITE_TOKEN), so `make apply` can dual-write ENC data to encapi via # the encapi Terraform provider. --- rules: - path: "kv/data/kubernetes/namespace/encapi/default/environment" capabilities: - read auth: approle: - terraform_incus