terraform-vault/auth_approle_terraform_repoflow.tf
Ben Vincent 4f185d5e28 feat: add policy to read terraform vars
- read variables required for terraform-repoflow
2025-12-13 10:56:58 +11:00

18 lines
441 B
HCL

resource "vault_approle_auth_backend_role" "terraform_repoflow" {
role_name = "terraform_repoflow"
bind_secret_id = false
token_policies = [
"default_access",
"kv/service/repoflow/unkinadmin/tokens/terraform/read",
"kv/service/terraform/repoflow",
]
token_ttl = 60
token_max_ttl = 120
token_bound_cidrs = [
"10.10.12.200/32",
"198.18.25.102/32",
"198.18.26.91/32",
"198.18.27.40/32",
]
}