# Let the terraform-vault deployer read the OpenBao OIDC client credentials that # Authentik's provider module generates and writes here (terraform_authentik owns # kv/service/authentik/* — see policies/kv/service/authentik/write.yaml). The # deployer consumes client_id/client_secret to configure the auth/oidc backend. # # OIDC becomes the default human auth path; approle and k8s (CI and agents) plus # the break-glass root path are unchanged. # # AppRole capabilities are fixed at login, so this grant must be applied before # the PR that adds the auth/oidc modules. --- rules: - path: "kv/data/service/authentik/oidc-vault" capabilities: - read auth: approle: - tf_vault k8s/au/syd1: - woodpecker_terraform_vault