Vault - orchestrator-policy-kv2.hcl (reader)
Vault Solution · Config document · referenced from Authentication and policies
The policy of the orchestration platform, the system that consumes customer secrets to configure devices and cloud accounts. It reads every object type and manages exactly one, the VPN credentials it generates itself in automatic mode.
| Item | Value |
|---|---|
| Path on the host | /etc/vault.d/policy/orchestrator-policy-kv2_v03.hcl |
| Policy name in Vault | orchestrator-policy-kv2 |
| Loaded on | PROD and NONPROD |
| Used by | AppRole orchestrator-kv2 |
| Object type names | generalised for publication; the structure of every rule is as built |
The file
############################################################################ # ORCHESTRATOR POLICY - KV2 (New data structure) ############################################################################ ############################################################################ # This policy allows traversing the whole "kv2/*" (Key-Value) data structure, # but no secret is possible to read. ############################################################################ path "kv2/*" { capabilities = ["list"] } ############################################################################ # Secure web gateway - partner admin credentials ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/webGatewayCredentials/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator is allowed only to read (operations READ, LIST) # secure web gateway admin credentials for all customers. # # Keys: # - adminAccount # - adminApiKey # - adminPassword # -------------------------------------------------------------------------- path "kv2/+/+/webGatewayCredentials/+" { capabilities = ["read", "list"] } ############################################################################ # Secure web gateway - VPN credentials - automatic mode ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/webGatewayVpnAuto/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator is allowed to manage (operations CREATE, READ, UPDATE, DELETE, # LIST and PATCH) # VPN credentials for automatic mode for all customers. # # Keys: # - primaryGatewayFqdn # - primaryGatewayPsk # - secondaryGatewayFqdn # - secondaryGatewayPsk # -------------------------------------------------------------------------- path "kv2/+/+/web-gateway-vpn-auto/+" { capabilities = ["create", "read", "update", "delete", "list", "patch"] } ############################################################################ # Secure web gateway - VPN credentials - manual mode ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/webGatewayVpnManual/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator is allowed only to read (operations READ, LIST) # VPN credentials for manual mode for all customers. # # Keys: # - primaryGatewayFqdn # - primaryGatewayPsk # - secondaryGatewayFqdn # - secondaryGatewayPsk # -------------------------------------------------------------------------- path "kv2/+/+/webGatewayVpnManual/+" { capabilities = ["read", "list"] } ############################################################################ # Public cloud (AWS) - credentials ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/cloudAwsCredentials/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator is allowed only to read (operations READ, LIST) # AWS credentials for all customers. # # Keys: # - accessKey # - secretKey # - assumeRoleArn # -------------------------------------------------------------------------- path "kv2/+/+/cloudAwsCredentials/+" { capabilities = ["read", "list"] } ############################################################################ # Public cloud (Azure) - credentials ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/cloudAzureCredentials/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator is allowed only to read (operations READ, LIST) # Azure credentials for all customers. # # Keys: # - clientId # - clientSecret # - tenantId # - subscriptionId # -------------------------------------------------------------------------- path "kv2/+/+/cloudAzureCredentials/+" { capabilities = ["read", "list"] } ############################################################################ # Public cloud (GCP) - credentials ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/cloudGcpCredentials/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator is allowed only to read (operations READ, LIST) # GCP credentials for all customers. # # Keys: # - projectId # - clientId # - privateKeyId # - privateKey # - serviceAccountEmail # -------------------------------------------------------------------------- path "kv2/+/+/cloudGcpCredentials/+" { capabilities = ["read", "list"] } ############################################################################ # Shared object (certificate) - private key - customer provided ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/certificateCustomer/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator is allowed only to read (operations READ, LIST) # customer certificate keys for all customers. # # Keys: # - certificateKey # - certificateKeyPassphrase # -------------------------------------------------------------------------- path "kv2/+/+/certificateCustomer/+" { capabilities = ["read", "list"] } ############################################################################ # BGP and OSPF routing - authentication key ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/routingAuthKey/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator is allowed only to read (operations READ, LIST) # BGP and OSPF authentication keys for all customers. # # Keys: # - authKey # -------------------------------------------------------------------------- path "kv2/+/+/routingAuthKey/+" { capabilities = ["read", "list"] } ############################################################################ # IPsec IKE policy - pre-shared key ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/ipsecPreSharedKey/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator is allowed only to read (operations READ, LIST) # IPsec IKE pre-shared keys for all customers. # # Keys: # - preSharedKey # -------------------------------------------------------------------------- path "kv2/+/+/ipsecPreSharedKey/+" { capabilities = ["read", "list"] }
As-built quirk
The rule for automatic-mode VPN credentials uses the path segment web-gateway-vpn-auto, while the data structure and the other two policies name the type webGatewayVpnAuto. The hyphenated spelling is a leftover of the old KV v1 naming. With the rule as written, the orchestrator could not reach objects stored under the camel-case name; the mismatch is kept here because it is what the file said.
Checked against Vault 2.1
- KV v2 paths are unchanged. A secret is read and written under
data/, listed and deleted for good undermetadata/, and soft-deleted, restored and destroyed underdelete/,undelete/anddestroy/. Thepatchcapability still exists. kv2/+/+/<type>/+is broader than it looks. The first+matches every one of those prefixes, so a rule meant as "write the secret" also grantsmetadata,delete,undeleteanddestroyfor the same object. A tighter policy names the prefixes it needs:kv2/data/+/<type>/+for the content andkv2/metadata/+/<type>/+for listing and removal.allowed_parameters,denied_parametersandrequired_parametersstill do not work on KV v2. The old KV v1 policies restricted which keys could be written; that control was lost in the migration and cannot be rebuilt in a policy.- A key written twice in one block is an error since 1.21. This file has none.
See policies and the KV v2 API.