Vault - service-portal-policy-kv2.hcl (writer)
Vault Solution · Config document · referenced from Authentication and policies
The policy of the customer portal, the system in which a customer types a secret. It can create, update and delete every object type and cannot read any of them back: read is missing from every rule on purpose.
| Item | Value |
|---|---|
| Path on the host | /etc/vault.d/policy/service-portal-policy-kv2_v03.hcl |
| Policy name in Vault | service-portal-policy-kv2 |
| Loaded on | PROD and NONPROD |
| Used by | AppRole service-portal-kv2 |
| Object type names | generalised for publication; the structure of every rule is as built |
The file
############################################################################ # SERVICE-PORTAL POLICY - KV2 (New data structure) ############################################################################ ############################################################################ # This policy allows traversing the whole "kv2/*" (Key-Value) data structure, # but no secret is possible to read. ############################################################################ path "kv2/*" { capabilities = ["list"] } ############################################################################ # Secure web gateway - partner admin credentials ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/webGatewayCredentials/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # service-portal is allowed to write but not to read (operations CREATE, UPDATE, # DELETE, LIST and PATCH) # secure web gateway admin credentials for all customers. # # Keys: # - adminAccount # - adminApiKey # - adminPassword # -------------------------------------------------------------------------- path "kv2/+/+/webGatewayCredentials/+" { capabilities = ["create", "update", "delete", "list", "patch"] } ############################################################################ # Secure web gateway - VPN credentials - manual mode ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/webGatewayVpnManual/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # service-portal is allowed to write but not to read (operations CREATE, UPDATE, # DELETE, LIST and PATCH) # VPN credentials for manual mode for all customers. # # Keys: # - primaryGatewayFqdn # - primaryGatewayPsk # - secondaryGatewayFqdn # - secondaryGatewayPsk # -------------------------------------------------------------------------- path "kv2/+/+/webGatewayVpnManual/+" { capabilities = ["create", "update", "delete", "list", "patch"] } ############################################################################ # Public cloud (AWS) - credentials ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/cloudAwsCredentials/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # service-portal is allowed to write but not to read (operations CREATE, UPDATE, # DELETE, LIST and PATCH) # AWS credentials for all customers. # # Keys: # - accessKey # - secretKey # - assumeRoleArn # -------------------------------------------------------------------------- path "kv2/+/+/cloudAwsCredentials/+" { capabilities = ["create", "update", "delete", "list", "patch"] } ############################################################################ # Public cloud (Azure) - credentials ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/cloudAzureCredentials/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # service-portal is allowed to write but not to read (operations CREATE, UPDATE, # DELETE, LIST and PATCH) # Azure credentials for all customers. # # Keys: # - clientId # - clientSecret # - tenantId # - subscriptionId # -------------------------------------------------------------------------- path "kv2/+/+/cloudAzureCredentials/+" { capabilities = ["create", "update", "delete", "list", "patch"] } ############################################################################ # Public cloud (GCP) - credentials ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/cloudGcpCredentials/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # service-portal is allowed to write but not to read (operations CREATE, UPDATE, # DELETE, LIST and PATCH) # GCP credentials for all customers. # # Keys: # - projectId # - clientId # - privateKeyId # - privateKey # - serviceAccountEmail # -------------------------------------------------------------------------- path "kv2/data/+/cloudGcpCredentials/+" { capabilities = ["create", "update", "delete", "list", "patch"] } ############################################################################ # Shared object (certificate) - private key - customer provided ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/certificateCustomer/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # service-portal is allowed to write but not to read (operations CREATE, UPDATE, # DELETE, LIST and PATCH) # customer certificate keys for all customers. # # Keys: # - certificateKey # - certificateKeyPassphrase # -------------------------------------------------------------------------- path "kv2/+/+/certificateCustomer/+" { capabilities = ["create", "update", "delete", "list", "patch"] } ############################################################################ # BGP and OSPF routing - authentication key ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/routingAuthKey/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # service-portal is allowed to write but not to read (operations CREATE, UPDATE, # DELETE, LIST and PATCH) # BGP and OSPF authentication keys for all customers. # # Keys: # - authKey # -------------------------------------------------------------------------- path "kv2/+/+/routingAuthKey/+" { capabilities = ["create", "update", "delete", "list", "patch"] } ############################################################################ # IPsec IKE policy - pre-shared key ############################################################################ # Data structure # -------------------------------------------------------------------------- # "kv2/data/<customerExternalId>/ipsecPreSharedKey/<UUID>" # # Variables: # - <customerExternalId> = Unique identifier of the customer. # - <UUID> = Unique identifier of the object (generated by # the writer). # -------------------------------------------------------------------------- # Permissions # -------------------------------------------------------------------------- # service-portal is allowed to write but not to read (operations CREATE, UPDATE, # DELETE, LIST and PATCH) # IPsec IKE pre-shared keys for all customers. # # Keys: # - preSharedKey # -------------------------------------------------------------------------- path "kv2/+/+/ipsecPreSharedKey/+" { capabilities = ["create", "update", "delete", "list", "patch"] }
As-built quirks
- There is no rule for
webGatewayVpnAuto: in automatic mode the orchestrator creates those credentials, and the portal never touches them. - The GCP rule is written
kv2/data/+/cloudGcpCredentials/+, withdataspelled out, while every other rule useskv2/+/+/…. The spelled-out form is the tighter one; see the section below.
Checked against Vault 2.1
- KV v2 paths are unchanged. A secret is read and written under
data/, listed and deleted for good undermetadata/, and soft-deleted, restored and destroyed underdelete/,undelete/anddestroy/. Thepatchcapability still exists. kv2/+/+/<type>/+is broader than it looks. The first+matches every one of those prefixes, so a rule meant as "write the secret" also grantsmetadata,delete,undeleteanddestroyfor the same object. A tighter policy names the prefixes it needs:kv2/data/+/<type>/+for the content andkv2/metadata/+/<type>/+for listing and removal.allowed_parameters,denied_parametersandrequired_parametersstill do not work on KV v2. The old KV v1 policies restricted which keys could be written; that control was lost in the migration and cannot be rebuilt in a policy.- A key written twice in one block is an error since 1.21. This file has none.
See policies and the KV v2 API.