724fcf2a76
Why: applying the forthcoming gitea_secret_backend + role config from terraform-vault requires the deployment identity (tf_vault approle / woodpecker_terraform_vault k8s role) to write the engine's config and roles. Without it, the engine apply 403s. This mirrors policies/rancher/admin.yaml. Change: - Add policies/gitea/admin.yaml granting create/read/update/delete on gitea/config, create/update on gitea/config/rotate-root, and full manage on gitea/roles/*; excludes gitea/creds/* (minting is for consumers). - Catalog registration is already covered by the shared wildcard grant in policies/sys/plugins/catalog/admin.yaml and mounting uses existing sys/mounts/* access, so no new catalog/mount grant is added (matches rancher). Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv