# Allow the terragrunt-enc runner to generate credentials for the # terraform-enc role in consul (used to lock/write its terragrunt state under # infra/terraform/enc/ on the consul backend). --- rules: - path: "consul_root/au/syd1/creds/terraform-enc" capabilities: - read auth: approle: - terraform_enc k8s/au/syd1: - woodpecker_terraform_enc