LINUXOR.SK ... open source notes ...

Vault - snapshots-policy.hcl (snapshot agent)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Authentication and policies, Raft snapshots, backup and restore

The whole policy of the Raft snapshot agent: one path, one capability. The AppRole that carries it can download a snapshot and do nothing else.

ItemValue
Path on the host/etc/vault.d/policy/snapshots-policy_v01.hcl
Policy name in Vaultsnapshots-policy
Loaded onPROD, NONPROD and COMMON
Used byAppRole snapshots, with token_no_default_policy=true

The file

hcl
############################################################################
# SNAPSHOTS POLICY
############################################################################

############################################################################
# Snapshot permissions
############################################################################

# Read snapshots
path "/sys/storage/raft/snapshot"
{
  capabilities = ["read"]
}

Checked against Vault 2.1

The path sys/storage/raft/snapshot and the read capability are unchanged. The leading slash in the path is tolerated and unnecessary; write sys/storage/raft/snapshot. See the raft operator commands.

← solutionz