Page MenuHomeDevCentral

D3355.id8653.diff
No OneTemporary

D3355.id8653.diff

diff --git a/roles/vault/policies/files/salt-primary.hcl b/roles/vault/policies/files/salt-primary.hcl
--- a/roles/vault/policies/files/salt-primary.hcl
+++ b/roles/vault/policies/files/salt-primary.hcl
@@ -37,6 +37,7 @@
# Tokens management
#
# :: Create, check, revoke tokens to be used by nodes through Salt
+# :: Create admin token as self-service for ops members
# :: Manage and renew own token
# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
@@ -48,6 +49,14 @@
capabilities = ["read"]
}
+path "auth/token/create/admin" {
+ capabilities = ["update"]
+}
+
+path "auth/token/roles/admin" {
+ capabilities = ["read"]
+}
+
path "auth/token/lookup-self" {
capabilities = ["read"]
}

File Metadata

Mime Type
text/plain
Expires
Fri, Jan 31, 10:57 (8 h, 27 m)
Storage Engine
blob
Storage Format
Raw Data
Storage Handle
2387738
Default Alt Text
D3355.id8653.diff (734 B)

Event Timeline