# Allow the terragrunt-enc runner to read the encapi environment secret # (ENCAPI_WRITE_TOKEN), so `make apply` can write ENC data (statuses, roles, # nodes) to encapi via the encapi Terraform provider. --- rules: - path: "kv/data/kubernetes/namespace/encapi/default/environment" capabilities: - read auth: approle: - terraform_enc k8s/au/syd1: - woodpecker_terraform_enc