acme-to-vault/vault/policies/acme-to-vault.hcl

18 lines
506 B
HCL

path "[[ .vault.prefix ]]kv/data/service/+/certs/*" {
capabilities = ["read","create","update"]
}
path "[[ .vault.prefix ]]kv/metadata/service/+/certs" {
capabilities = ["list","read"]
}
path "[[ .vault.prefix ]]kv/data/service/[[ .instance ]]/account/*" {
capabilities = ["read","create","update"]
}
path "[[ .vault.prefix ]]kv/metadata/service/[[ .instance ]]/account/*" {
capabilities = ["list","read"]
}
path "[[ .vault.prefix ]]kv/data/service/[[ .instance ]]" {
capabilities = ["read"]
}