LINUXOR.SK ... open source notes ...

Vault - service-portal-policy-kv2.hcl (writer)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Authentication and policies

The policy of the customer portal, the system in which a customer types a secret. It can create, update and delete every object type and cannot read any of them back: read is missing from every rule on purpose.

ItemValue
Path on the host/etc/vault.d/policy/service-portal-policy-kv2_v03.hcl
Policy name in Vaultservice-portal-policy-kv2
Loaded onPROD and NONPROD
Used byAppRole service-portal-kv2
Object type namesgeneralised for publication; the structure of every rule is as built

The file

hcl
############################################################################
# SERVICE-PORTAL POLICY - KV2 (New data structure)
############################################################################

############################################################################
# This policy allows traversing the whole "kv2/*" (Key-Value) data structure,
# but no secret is possible to read.
############################################################################
path "kv2/*" {
  capabilities = ["list"]
}

############################################################################
# Secure web gateway - partner admin credentials
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/webGatewayCredentials/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# service-portal is allowed to write but not to read (operations CREATE, UPDATE,
# DELETE, LIST and PATCH)
# secure web gateway admin credentials for all customers.
#
# Keys:
# - adminAccount
# - adminApiKey
# - adminPassword
# --------------------------------------------------------------------------
path "kv2/+/+/webGatewayCredentials/+" {
  capabilities = ["create", "update", "delete", "list", "patch"]
}

############################################################################
# Secure web gateway - VPN credentials - manual mode
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/webGatewayVpnManual/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# service-portal is allowed to write but not to read (operations CREATE, UPDATE,
# DELETE, LIST and PATCH)
# VPN credentials for manual mode for all customers.
#
# Keys:
# - primaryGatewayFqdn
# - primaryGatewayPsk
# - secondaryGatewayFqdn
# - secondaryGatewayPsk
# --------------------------------------------------------------------------
path "kv2/+/+/webGatewayVpnManual/+" {
  capabilities = ["create", "update", "delete", "list", "patch"]
}

############################################################################
# Public cloud (AWS) - credentials
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/cloudAwsCredentials/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# service-portal is allowed to write but not to read (operations CREATE, UPDATE,
# DELETE, LIST and PATCH)
# AWS credentials for all customers.
#
# Keys:
# - accessKey
# - secretKey
# - assumeRoleArn
# --------------------------------------------------------------------------
path "kv2/+/+/cloudAwsCredentials/+" {
  capabilities = ["create", "update", "delete", "list", "patch"]
}

############################################################################
# Public cloud (Azure) - credentials
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/cloudAzureCredentials/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# service-portal is allowed to write but not to read (operations CREATE, UPDATE,
# DELETE, LIST and PATCH)
# Azure credentials for all customers.
#
# Keys:
# - clientId
# - clientSecret
# - tenantId
# - subscriptionId
# --------------------------------------------------------------------------
path "kv2/+/+/cloudAzureCredentials/+" {
  capabilities = ["create", "update", "delete", "list", "patch"]
}

############################################################################
# Public cloud (GCP) - credentials
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/cloudGcpCredentials/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# service-portal is allowed to write but not to read (operations CREATE, UPDATE,
# DELETE, LIST and PATCH)
# GCP credentials for all customers.
#
# Keys:
# - projectId
# - clientId
# - privateKeyId
# - privateKey
# - serviceAccountEmail
# --------------------------------------------------------------------------
path "kv2/data/+/cloudGcpCredentials/+" {
  capabilities = ["create", "update", "delete", "list", "patch"]
}

############################################################################
# Shared object (certificate) - private key - customer provided
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/certificateCustomer/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# service-portal is allowed to write but not to read (operations CREATE, UPDATE,
# DELETE, LIST and PATCH)
# customer certificate keys for all customers.
#
# Keys:
# - certificateKey
# - certificateKeyPassphrase
# --------------------------------------------------------------------------
path "kv2/+/+/certificateCustomer/+" {
  capabilities = ["create", "update", "delete", "list", "patch"]
}

############################################################################
# BGP and OSPF routing - authentication key
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/routingAuthKey/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# service-portal is allowed to write but not to read (operations CREATE, UPDATE,
# DELETE, LIST and PATCH)
# BGP and OSPF authentication keys for all customers.
#
# Keys:
# - authKey
# --------------------------------------------------------------------------
path "kv2/+/+/routingAuthKey/+" {
  capabilities = ["create", "update", "delete", "list", "patch"]
}

############################################################################
# IPsec IKE policy - pre-shared key
############################################################################
# Data structure
# --------------------------------------------------------------------------
# "kv2/data/<customerExternalId>/ipsecPreSharedKey/<UUID>"
#
# Variables:
# - <customerExternalId> = Unique identifier of the customer.
# - <UUID>               = Unique identifier of the object (generated by
#                          the writer).
# --------------------------------------------------------------------------
# Permissions
# --------------------------------------------------------------------------
# service-portal is allowed to write but not to read (operations CREATE, UPDATE,
# DELETE, LIST and PATCH)
# IPsec IKE pre-shared keys for all customers.
#
# Keys:
# - preSharedKey
# --------------------------------------------------------------------------
path "kv2/+/+/ipsecPreSharedKey/+" {
  capabilities = ["create", "update", "delete", "list", "patch"]
}

As-built quirks

Checked against Vault 2.1

See policies and the KV v2 API.

← solutionz