LINUXOR.SK ... open source notes ...

Vault - orchestrator-policy-kv2.hcl (reader)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Authentication and policies

The policy of the orchestration platform, the system that consumes customer secrets to configure devices and cloud accounts. It reads every object type and manages exactly one, the VPN credentials it generates itself in automatic mode.

ItemValue
Path on the host/etc/vault.d/policy/orchestrator-policy-kv2_v03.hcl
Policy name in Vaultorchestrator-policy-kv2
Loaded onPROD and NONPROD
Used byAppRole orchestrator-kv2
Object type namesgeneralised for publication; the structure of every rule is as built

The file

hcl
############################################################################
# ORCHESTRATOR POLICY - KV2 (New data structure)
############################################################################

############################################################################
# This policy allows traversing the whole "kv2/*" (Key-Value) data structure,
# but no secret is possible to read.
############################################################################
path "kv2/*" {
  capabilities = ["list"]
}

############################################################################
# Secure web gateway - partner admin credentials
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/webGatewayCredentials/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator is allowed only to read (operations READ, LIST)
# secure web gateway admin credentials for all customers.
#
# Keys:
# - adminAccount
# - adminApiKey
# - adminPassword
# --------------------------------------------------------------------------
path "kv2/+/+/webGatewayCredentials/+" {
  capabilities = ["read", "list"]
}

############################################################################
# Secure web gateway - VPN credentials - automatic mode
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/webGatewayVpnAuto/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator is allowed to manage (operations CREATE, READ, UPDATE, DELETE,
# LIST and PATCH)
# VPN credentials for automatic mode for all customers.
#
# Keys:
# - primaryGatewayFqdn
# - primaryGatewayPsk
# - secondaryGatewayFqdn
# - secondaryGatewayPsk
# --------------------------------------------------------------------------
path "kv2/+/+/web-gateway-vpn-auto/+" {
  capabilities = ["create", "read", "update", "delete", "list", "patch"]
}

############################################################################
# Secure web gateway - VPN credentials - manual mode
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/webGatewayVpnManual/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator is allowed only to read (operations READ, LIST)
# VPN credentials for manual mode for all customers.
#
# Keys:
# - primaryGatewayFqdn
# - primaryGatewayPsk
# - secondaryGatewayFqdn
# - secondaryGatewayPsk
# --------------------------------------------------------------------------
path "kv2/+/+/webGatewayVpnManual/+" {
  capabilities = ["read", "list"]
}

############################################################################
# Public cloud (AWS) - credentials
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/cloudAwsCredentials/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator is allowed only to read (operations READ, LIST)
# AWS credentials for all customers.
#
# Keys:
# - accessKey
# - secretKey
# - assumeRoleArn
# --------------------------------------------------------------------------
path "kv2/+/+/cloudAwsCredentials/+" {
  capabilities = ["read", "list"]
}

############################################################################
# Public cloud (Azure) - credentials
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/cloudAzureCredentials/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator is allowed only to read (operations READ, LIST)
# Azure credentials for all customers.
#
# Keys:
# - clientId
# - clientSecret
# - tenantId
# - subscriptionId
# --------------------------------------------------------------------------
path "kv2/+/+/cloudAzureCredentials/+" {
  capabilities = ["read", "list"]
}

############################################################################
# Public cloud (GCP) - credentials
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/cloudGcpCredentials/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator is allowed only to read (operations READ, LIST)
# GCP credentials for all customers.
#
# Keys:
# - projectId
# - clientId
# - privateKeyId
# - privateKey
# - serviceAccountEmail
# --------------------------------------------------------------------------
path "kv2/+/+/cloudGcpCredentials/+" {
  capabilities = ["read", "list"]
}

############################################################################
# Shared object (certificate) - private key - customer provided
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/certificateCustomer/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator is allowed only to read (operations READ, LIST)
# customer certificate keys for all customers.
#
# Keys:
# - certificateKey
# - certificateKeyPassphrase
# --------------------------------------------------------------------------
path "kv2/+/+/certificateCustomer/+" {
  capabilities = ["read", "list"]
}

############################################################################
# BGP and OSPF routing - authentication key
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/routingAuthKey/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator is allowed only to read (operations READ, LIST)
# BGP and OSPF authentication keys for all customers.
#
# Keys:
# - authKey
# --------------------------------------------------------------------------
path "kv2/+/+/routingAuthKey/+" {
  capabilities = ["read", "list"]
}

############################################################################
# IPsec IKE policy - pre-shared key
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/ipsecPreSharedKey/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator is allowed only to read (operations READ, LIST)
# IPsec IKE pre-shared keys for all customers.
#
# Keys:
# - preSharedKey
# --------------------------------------------------------------------------
path "kv2/+/+/ipsecPreSharedKey/+" {
  capabilities = ["read", "list"]
}

As-built quirk

The rule for automatic-mode VPN credentials uses the path segment web-gateway-vpn-auto, while the data structure and the other two policies name the type webGatewayVpnAuto. The hyphenated spelling is a leftover of the old KV v1 naming. With the rule as written, the orchestrator could not reach objects stored under the camel-case name; the mismatch is kept here because it is what the file said.

Checked against Vault 2.1

See policies and the KV v2 API.

← solutionz