# Allow the terraform-vault deployer to read the seeded arrproxy admin token so # the arrstack engine config module can source it. The token is seeded by # argocd-apps #384 at kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token. # The deployer's existing secret_backends_read policy only covers # kv/data/service/vault/+/+/secret_backend/*, which does not match this # kubernetes/namespace path, so this adds the minimal read grant rather than # duplicating the secret into the litellm-style path. vault_kv_secret_v2 also # reads the kv-v2 metadata path on every plan/apply, so grant that too. --- rules: - path: "kv/data/kubernetes/namespace/arrstack/default/arrproxy-admin-token" capabilities: - read - path: "kv/metadata/kubernetes/namespace/arrstack/default/arrproxy-admin-token" capabilities: - read auth: approle: - tf_vault k8s/au/syd1: - woodpecker_terraform_vault