Files
terraform-vault/policies
unkinben 724fcf2a76
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
policies: grant the vault deployer access to the gitea secrets engine
Why: applying the forthcoming gitea_secret_backend + role config from
terraform-vault requires the deployment identity (tf_vault approle /
woodpecker_terraform_vault k8s role) to write the engine's config and roles.
Without it, the engine apply 403s. This mirrors policies/rancher/admin.yaml.

Change:
- Add policies/gitea/admin.yaml granting create/read/update/delete on
  gitea/config, create/update on gitea/config/rotate-root, and full manage
  on gitea/roles/*; excludes gitea/creds/* (minting is for consumers).
- Catalog registration is already covered by the shared wildcard grant in
  policies/sys/plugins/catalog/admin.yaml and mounting uses existing
  sys/mounts/* access, so no new catalog/mount grant is added (matches rancher).

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
2026-07-27 19:02:08 +10:00
..
2026-05-21 23:52:30 +10:00
2026-05-21 23:52:30 +10:00
2026-05-21 23:52:30 +10:00
2026-05-21 23:52:30 +10:00
2026-05-21 23:52:30 +10:00
2026-05-21 23:52:30 +10:00
2026-05-21 23:52:30 +10:00
2026-05-21 23:52:30 +10:00