terraform-vault/auth_approle_rpmbuilder.tf
Ben Vincent 0776fac6eb chore: fix policies for rpmbuilder
- missed the `/read` on the end
2025-11-30 21:24:06 +11:00

17 lines
429 B
HCL

resource "vault_approle_auth_backend_role" "rpmbuilder" {
role_name = "rpmbuilder"
bind_secret_id = false
token_policies = [
"kv/service/github/neoloc/tokens/read-only-token/read",
"kv/service/gitea/unkinben/tokens/read-only-packages/read",
]
token_ttl = 30
token_max_ttl = 30
token_bound_cidrs = [
"10.10.12.200/32",
"198.18.25.102/32",
"198.18.26.91/32",
"198.18.27.40/32",
]
}