# Allow the vault deployer to manage the gitea token secrets engine: its # connection config (seeded admin credentials), in-place root rotation, and # token-minting roles. # # Scoped to gitea/* only, and deliberately excludes gitea/creds/* — minting # tokens is for consumers, not the deployer. The plugin-catalog grant needed to # import the plugin is the shared, sudo-protected wildcard in # policies/sys/plugins/catalog/admin.yaml (already covers this plugin), and # mounting the engine uses the deployer's existing sys/mounts/* access, so no # new catalog/mount grant is added here (mirrors the rancher engine). --- rules: # Engine connection config (Gitea URL, TLS, seeded admin username/password). - path: "gitea/config" capabilities: - create - read - update - delete # In-place rotation of the seeded admin password (write-only trigger). - path: "gitea/config/rotate-root" capabilities: - create - update # Token-minting roles. - path: "gitea/roles/*" capabilities: - create - read - update - delete - list - path: "gitea/roles" capabilities: - read - list auth: approle: - tf_vault k8s/au/syd1: - woodpecker_terraform_vault