# Allow full administration of the OIDC auth backend (mount config and login # roles), mirroring policies/auth/ldap/admin.yaml. sys/auth/* already covers # enabling the mount itself; this covers writing auth/oidc/config and # auth/oidc/role/*. --- rules: - path: "auth/oidc/*" capabilities: - create - update - read - delete - list auth: approle: - tf_vault k8s/au/syd1: - woodpecker_terraform_vault