Allow to add to every node policy keys from the new pillar entry
vault_secrets_ubiquity.
Ref T2268
Differential D3987
Allow all servers to read IPsec in Vault Authored by Duranzed on Mon, Mar 2, 18:15. Tags None Referenced Files
Subscribers None
Details
Allow to add to every node policy keys from the new pillar entry Ref T2268 salt complector state.sls_id salt-node-cloudhugger roles/vault/policies test=True
Diff Detail
Event TimelineComment Actions $ sudo salt complector state.sls_id salt-node-cloudhugger roles/vault/policies test=True complector: ---------- ID: salt-node-cloudhugger Function: vault.policy_present Result: None Comment: Policy would be changed Started: 18:09:21.668208 Duration: 841.275 ms Changes: ---------- salt-node-cloudhugger: ---------- change: --- +++ @@ -10,3 +10,7 @@ path "ops/data/secrets/nasqueron/opensearch/infra-logs/internal_users/dashboards" { capabilities = [ "read" ] } + +path "ops/data/secrets/network/ipsec/key" { + capabilities = [ "read" ] +} Summary for complector ------------ Succeeded: 1 (unchanged=1, changed=1) Failed: 0 ------------ Total states run: 1 Total run time: 841.275 ms |