ctctl/vault/policies/admin.hcl

91 lines
2.0 KiB
HCL

# Read system health check
path "sys/health" {
capabilities = ["read", "sudo"]
}
path "sys/metrics" {
capabilities = ["read", "list"]
}
# Create and manage ACL policies broadly across Vault
# List existing policies
path "sys/policies/acl" {
capabilities = ["list"]
}
# Create and manage ACL policies
path "sys/policies/acl/*" {
capabilities = ["create", "read", "update", "delete", "list", "sudo"]
}
# List and manage password policies
path "sys/policies/password" {
capabilities = ["list"]
}
path "sys/policies/password/*" {
capabilities = ["create", "read", "update", "delete", "list", "sudo"]
}
# Revoke leases
path "sys/leases/revoke/*" {
capabilities = ["update"]
}
# Enable and manage authentication methods broadly across Vault
# Manage auth methods broadly across Vault
path "auth/*" {
capabilities = ["create", "read", "update", "delete", "list", "sudo"]
}
# Create, update, and delete auth methods
path "sys/auth/*" {
capabilities = ["create", "update", "delete", "sudo"]
}
# List auth methods
path "sys/auth" {
capabilities = ["read"]
}
# Enable and manage the key/value secrets engine at `secret/` path
# List, create, update, and delete key/value secrets
path "kv/*" {
capabilities = ["create", "read", "update", "delete", "list", "sudo", "patch"]
}
# Same for PKI
path "/pki/*" {
capabilities = ["create", "read", "update", "delete", "list", "sudo"]
}
# Manage consul, nomad and databases secrets
path "/consul/*" {
capabilities = ["create", "read", "update", "delete", "list", "sudo"]
}
path "/nomad/*" {
capabilities = ["create", "read", "update", "delete", "list", "sudo"]
}
path "/database/*" {
capabilities = ["create", "read", "update", "delete", "list", "sudo"]
}
# Manage transit engines
path "/transit/*" {
capabilities = ["create", "read", "update", "delete", "list", "sudo"]
}
# Manage secrets engines
path "sys/mounts/*" {
capabilities = ["create", "read", "update", "delete", "list", "sudo"]
}
# List existing secrets engines.
path "sys/mounts" {
capabilities = ["read"]
}