LINUXOR.SK ... open source notes ...

Vault - orchestrator-ui-policy-kv2.hcl (manager)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Authentication and policies

The policy of the orchestration platform's own operator interface for Vault data. It manages every object type for every customer and is the broadest of the three consumer policies.

ItemValue
Path on the host/etc/vault.d/policy/orchestrator-ui-policy-kv2_v03.hcl
Policy name in Vaultorchestrator-ui-policy-kv2
Loaded onPROD and NONPROD
Used byAppRole orchestrator-ui-kv2
Object type namesgeneralised for publication; the structure of every rule is as built

The file

hcl
############################################################################
# ORCHESTRATOR-UI POLICY - KV2 (New data structure)
############################################################################

############################################################################
# This policy allows traversing the whole "kv2/*" (Key-Value) data structure,
# but no secret is possible to read.
############################################################################
path "kv2/*" {
  capabilities = ["list"]
}

############################################################################
# Secure web gateway - partner admin credentials
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/webGatewayCredentials/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST
# and PATCH)
# secure web gateway admin credentials for all customers.
#
# Keys:
# - adminAccount
# - adminApiKey
# - adminPassword
# --------------------------------------------------------------------------
path "kv2/+/+/webGatewayCredentials/+" {
  capabilities = ["read", "create", "update", "delete", "list", "patch"]
}

############################################################################
# Secure web gateway - VPN credentials - automatic mode
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/webGatewayVpnAuto/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST
# and PATCH)
# VPN credentials for automatic mode for all customers.
#
# Keys:
# - primaryGatewayFqdn
# - primaryGatewayPsk
# - secondaryGatewayFqdn
# - secondaryGatewayPsk
# --------------------------------------------------------------------------
path "kv2/+/+/webGatewayVpnAuto/+" {
  capabilities = ["read", "create", "update", "delete", "list", "patch"]
}

############################################################################
# Secure web gateway - VPN credentials - manual mode
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/webGatewayVpnManual/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST
# and PATCH)
# VPN credentials for manual mode for all customers.
#
# Keys:
# - primaryGatewayFqdn
# - primaryGatewayPsk
# - secondaryGatewayFqdn
# - secondaryGatewayPsk
# --------------------------------------------------------------------------
path "kv2/+/+/webGatewayVpnManual/+" {
  capabilities = ["read", "create", "update", "delete", "list", "patch"]
}

############################################################################
# Public cloud (AWS) - credentials
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/cloudAwsCredentials/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST
# and PATCH)
# AWS credentials for all customers.
#
# Keys:
# - accessKey
# - secretKey
# - assumeRoleArn
# --------------------------------------------------------------------------
path "kv2/+/+/cloudAwsCredentials/+" {
  capabilities = ["read", "create", "update", "delete", "list", "patch"]
}

############################################################################
# Public cloud (Azure) - credentials
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/cloudAzureCredentials/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST
# and PATCH)
# Azure credentials for all customers.
#
# Keys:
# - clientId
# - clientSecret
# - tenantId
# - subscriptionId
# --------------------------------------------------------------------------
path "kv2/+/+/cloudAzureCredentials/+" {
  capabilities = ["read", "create", "update", "delete", "list", "patch"]
}

############################################################################
# Public cloud (GCP) - credentials
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/cloudGcpCredentials/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST
# and PATCH)
# GCP credentials for all customers.
#
# Keys:
# - projectId
# - clientId
# - privateKeyId
# - privateKey
# - serviceAccountEmail
# --------------------------------------------------------------------------
path "kv2/+/+/cloudGcpCredentials/+" {
  capabilities = ["read", "create", "update", "delete", "list", "patch"]
}

############################################################################
# Shared object (certificate) - private key - customer provided
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/certificateCustomer/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST
# and PATCH)
# customer certificate keys for all customers.
#
# Keys:
# - certificateKey
# - certificateKeyPassphrase
# --------------------------------------------------------------------------
path "kv2/+/+/certificateCustomer/+" {
  capabilities = ["read", "create", "update", "delete", "list", "patch"]
}

############################################################################
# BGP and OSPF routing - authentication key
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/routingAuthKey/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST
# and PATCH)
# BGP and OSPF authentication keys for all customers.
#
# Keys:
# - authKey
# --------------------------------------------------------------------------
path "kv2/+/+/routingAuthKey/+" {
  capabilities = ["read", "create", "update", "delete", "list", "patch"]
}

############################################################################
# IPsec IKE policy - pre-shared key
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/ipsecPreSharedKey/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST
# and PATCH)
# IPsec IKE pre-shared keys for all customers.
#
# Keys:
# - preSharedKey
# --------------------------------------------------------------------------
path "kv2/+/+/ipsecPreSharedKey/+" {
  capabilities = ["read", "create", "update", "delete", "list", "patch"]
}

Checked against Vault 2.1

See policies and the KV v2 API.

← solutionz