Vault - snapshots-policy.hcl (snapshot agent)
Vault Solution · Config document · referenced from Authentication and policies, Raft snapshots, backup and restore
The whole policy of the Raft snapshot agent: one path, one capability. The AppRole that carries it can download a snapshot and do nothing else.
| Item | Value |
|---|---|
| Path on the host | /etc/vault.d/policy/snapshots-policy_v01.hcl |
| Policy name in Vault | snapshots-policy |
| Loaded on | PROD, NONPROD and COMMON |
| Used by | AppRole snapshots, with token_no_default_policy=true |
The file
############################################################################ # SNAPSHOTS POLICY ############################################################################ ############################################################################ # Snapshot permissions ############################################################################ # Read snapshots path "/sys/storage/raft/snapshot" { capabilities = ["read"] }
Checked against Vault 2.1
The path sys/storage/raft/snapshot and the read capability are unchanged. The leading slash in the path is tolerated and unnecessary; write sys/storage/raft/snapshot. See the raft operator commands.