1-add-zabbix-example-with-template-strings #2
12
policies/role-zabbix/role-zabbix.hcl
Normal file
12
policies/role-zabbix/role-zabbix.hcl
Normal file
@ -0,0 +1,12 @@
|
||||
# Allow listing secret parent-child connections (as in UI hierarchy). Subdir
|
||||
# underneath 'kv' secrets engine will remain hidden though, user has to
|
||||
# manually open up
|
||||
# ${VAULT_ADDR}/ui/vault/secrets/kv/list/for_{{identity.groups.ids.GROUPID.name}}
|
||||
path "kv/metadata/for_{{identity.groups.ids.GROUPID.name}}/*" {
|
||||
capabilities = ["list"]
|
||||
}
|
||||
|
||||
# Grant read-only access to secrets
|
||||
path "kv/data/for_{{identity.groups.ids.GROUPID.name}}/*" {
|
||||
capabilities = ["read"]
|
||||
}
|
Loading…
x
Reference in New Issue
Block a user