6d90d90b66
The new terragrunt-enc repo manages all encapi ENC data via Terraform and needs its own Vault/Consul plumbing, mirroring terraform-git/terraform-incus: CI auth, isolated consul state, and read access to the ENCAPI_WRITE_TOKEN. - Add approle role terraform_enc and k8s auth role woodpecker_terraform_enc (bound to the terraform-enc SA in the woodpecker namespace). - Add consul secret backend role + ACL rules granting write on infra/terraform/enc/ for its terragrunt state, plus a policy letting both auth roles read consul_root/au/syd1/creds/terraform-enc. - Grant both auth roles read on kv/data/kubernetes/namespace/encapi/default/environment (ENCAPI_WRITE_TOKEN).
15 lines
369 B
YAML
15 lines
369 B
YAML
# Allow the terragrunt-enc runner to generate credentials for the
|
|
# terraform-enc role in consul (used to lock/write its terragrunt state under
|
|
# infra/terraform/enc/ on the consul backend).
|
|
---
|
|
rules:
|
|
- path: "consul_root/au/syd1/creds/terraform-enc"
|
|
capabilities:
|
|
- read
|
|
|
|
auth:
|
|
approle:
|
|
- terraform_enc
|
|
k8s/au/syd1:
|
|
- woodpecker_terraform_enc
|