Vault - orchestrator-ui-policy-kv2.hcl (manager)
Vault Solution · Config document · referenced from Authentication and policies
The policy of the orchestration platform's own operator interface for Vault data. It manages every object type for every customer and is the broadest of the three consumer policies.
| Item | Value |
|---|---|
| Path on the host | /etc/vault.d/policy/orchestrator-ui-policy-kv2_v03.hcl |
| Policy name in Vault | orchestrator-ui-policy-kv2 |
| Loaded on | PROD and NONPROD |
| Used by | AppRole orchestrator-ui-kv2 |
| Object type names | generalised for publication; the structure of every rule is as built |
The file
############################################################################ # ORCHESTRATOR-UI POLICY - KV2 (New data structure) ############################################################################ ############################################################################ # This policy allows traversing the whole "kv2/*" (Key-Value) data structure, # but no secret is possible to read. ############################################################################ path "kv2/*" { capabilities = ["list"] } ############################################################################ # Secure web gateway - partner admin credentials ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/webGatewayCredentials/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST # and PATCH) # secure web gateway admin credentials for all customers. # # Keys: # - adminAccount # - adminApiKey # - adminPassword # -------------------------------------------------------------------------- path "kv2/+/+/webGatewayCredentials/+" { capabilities = ["read", "create", "update", "delete", "list", "patch"] } ############################################################################ # Secure web gateway - VPN credentials - automatic mode ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/webGatewayVpnAuto/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST # and PATCH) # VPN credentials for automatic mode for all customers. # # Keys: # - primaryGatewayFqdn # - primaryGatewayPsk # - secondaryGatewayFqdn # - secondaryGatewayPsk # -------------------------------------------------------------------------- path "kv2/+/+/webGatewayVpnAuto/+" { capabilities = ["read", "create", "update", "delete", "list", "patch"] } ############################################################################ # Secure web gateway - VPN credentials - manual mode ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/webGatewayVpnManual/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST # and PATCH) # VPN credentials for manual mode for all customers. # # Keys: # - primaryGatewayFqdn # - primaryGatewayPsk # - secondaryGatewayFqdn # - secondaryGatewayPsk # -------------------------------------------------------------------------- path "kv2/+/+/webGatewayVpnManual/+" { capabilities = ["read", "create", "update", "delete", "list", "patch"] } ############################################################################ # Public cloud (AWS) - credentials ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/cloudAwsCredentials/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST # and PATCH) # AWS credentials for all customers. # # Keys: # - accessKey # - secretKey # - assumeRoleArn # -------------------------------------------------------------------------- path "kv2/+/+/cloudAwsCredentials/+" { capabilities = ["read", "create", "update", "delete", "list", "patch"] } ############################################################################ # Public cloud (Azure) - credentials ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/cloudAzureCredentials/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST # and PATCH) # Azure credentials for all customers. # # Keys: # - clientId # - clientSecret # - tenantId # - subscriptionId # -------------------------------------------------------------------------- path "kv2/+/+/cloudAzureCredentials/+" { capabilities = ["read", "create", "update", "delete", "list", "patch"] } ############################################################################ # Public cloud (GCP) - credentials ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/cloudGcpCredentials/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST # and PATCH) # GCP credentials for all customers. # # Keys: # - projectId # - clientId # - privateKeyId # - privateKey # - serviceAccountEmail # -------------------------------------------------------------------------- path "kv2/+/+/cloudGcpCredentials/+" { capabilities = ["read", "create", "update", "delete", "list", "patch"] } ############################################################################ # Shared object (certificate) - private key - customer provided ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/certificateCustomer/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST # and PATCH) # customer certificate keys for all customers. # # Keys: # - certificateKey # - certificateKeyPassphrase # -------------------------------------------------------------------------- path "kv2/+/+/certificateCustomer/+" { capabilities = ["read", "create", "update", "delete", "list", "patch"] } ############################################################################ # BGP and OSPF routing - authentication key ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/routingAuthKey/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST # and PATCH) # BGP and OSPF authentication keys for all customers. # # Keys: # - authKey # -------------------------------------------------------------------------- path "kv2/+/+/routingAuthKey/+" { capabilities = ["read", "create", "update", "delete", "list", "patch"] } ############################################################################ # IPsec IKE policy - pre-shared key ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/ipsecPreSharedKey/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # orchestrator-ui is allowed to manage (operations READ, CREATE, UPDATE, DELETE, LIST # and PATCH) # IPsec IKE pre-shared keys for all customers. # # Keys: # - preSharedKey # -------------------------------------------------------------------------- path "kv2/+/+/ipsecPreSharedKey/+" { capabilities = ["read", "create", "update", "delete", "list", "patch"] }
Checked against Vault 2.1
- KV v2 paths are unchanged. A secret is read and written under
data/, listed and deleted for good undermetadata/, and soft-deleted, restored and destroyed underdelete/,undelete/anddestroy/. Thepatchcapability still exists. kv2/+/+/<type>/+is broader than it looks. The first+matches every one of those prefixes, so a rule meant as "write the secret" also grantsmetadata,delete,undeleteanddestroyfor the same object. A tighter policy names the prefixes it needs:kv2/data/+/<type>/+for the content andkv2/metadata/+/<type>/+for listing and removal.allowed_parameters,denied_parametersandrequired_parametersstill do not work on KV v2. The old KV v1 policies restricted which keys could be written; that control was lost in the migration and cannot be rebuilt in a policy.- A key written twice in one block is an error since 1.21. This file has none.
See policies and the KV v2 API.