Files
vault/policies/ducoterra.hcl
ducoterra ac1d3c16df Give ducoterra access to ssh key signing
ducoterra can now sign ssh keys.
2021-07-18 21:17:19 -04:00

32 lines
692 B
HCL

path "totp/keys/*" {
capabilities = ["update"]
}
path "totp/code/*" {
capabilities = ["read"]
}
path "secret/*" {
capabilities = ["create", "read", "update", "delete", "list"]
}
path "dnet_inter/*" {
capabilities = ["create", "read", "update", "delete", "list"]
}
path "ssh-client-signer/sign/*" {
capabilities = ["create", "read", "update", "delete", "list"]
}
path "ssh-client-signer/roles/*" {
capabilities = ["create", "read", "update", "delete", "list"]
}
path "ssh-host-signer/sign/*" {
capabilities = ["create", "read", "update", "delete", "list"]
}
path "ssh-host-signer/roles/*" {
capabilities = ["create", "read", "update", "delete", "list"]
}