Files
terraform-vault/config/auth_approle_role/approle/terraform_enc.yaml
T
unkinben 6d90d90b66
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/plan Pipeline was successful
Add terraform-enc auth, consul state role, and encapi token grant
The new terragrunt-enc repo manages all encapi ENC data via Terraform and
needs its own Vault/Consul plumbing, mirroring terraform-git/terraform-incus:
CI auth, isolated consul state, and read access to the ENCAPI_WRITE_TOKEN.

- Add approle role terraform_enc and k8s auth role woodpecker_terraform_enc
  (bound to the terraform-enc SA in the woodpecker namespace).
- Add consul secret backend role + ACL rules granting write on
  infra/terraform/enc/ for its terragrunt state, plus a policy letting both
  auth roles read consul_root/au/syd1/creds/terraform-enc.
- Grant both auth roles read on
  kv/data/kubernetes/namespace/encapi/default/environment (ENCAPI_WRITE_TOKEN).
2026-07-24 23:05:55 +10:00

10 lines
196 B
YAML

token_ttl: 120
token_max_ttl: 120
bind_secret_id: false
token_bound_cidrs:
- "10.10.12.200/32"
- "198.18.25.102/32"
- "198.18.26.91/32"
- "198.18.27.40/32"
use_deterministic_role_id: true