Source code for saltext.vault.modules.vault_policy
"""
Manage Vault (or OpenBao) policies.
.. versionadded:: 1.9.0
The functions in this module were extracted from :py:mod:`vault <saltext.vault.modules.vault>`.
.. important::
This module requires the general :ref:`Vault setup <vault-setup>`.
"""
import logging
from typing import TYPE_CHECKING
from salt.exceptions import CommandExecutionError
from salt.exceptions import SaltException
from saltext.vault.utils import vault
if TYPE_CHECKING:
from saltext.vault.utils._types import SaltContext
from saltext.vault.utils._types import SaltFunctions
from saltext.vault.utils._types import SaltGrains
from saltext.vault.utils._types import SaltLogger
from saltext.vault.utils._types import SaltOpts
__opts__: SaltOpts
__context__: SaltContext
__salt__: SaltFunctions
__grains__: SaltGrains
log: "SaltLogger" = logging.getLogger(__name__) # type: ignore
__func_alias__ = {"list_": "list"}
__virtualname__ = "vault_policy"
[docs]
def fetch(policy):
"""
Fetch the rules associated with an ACL policy. Returns ``None`` if the policy
does not exist.
CLI Example:
.. code-block:: bash
salt '*' vault_policy.fetch salt_minion
Required policy:
.. code-block:: vaultpolicy
path "sys/policy/<policy>" {
capabilities = ["read"]
}
policy
Name of the policy to fetch.
"""
# there is also "sys/policies/acl/{policy}"
endpoint = f"sys/policy/{policy}"
try:
data = vault.api_get(endpoint, __opts__, __context__)
return data["rules"]
except vault.VaultNotFoundError:
return None
except SaltException as err:
raise CommandExecutionError(f"{type(err).__name__}: {err}") from err
[docs]
def write(policy, rules):
r"""
Create or update an ACL policy.
CLI Example:
.. code-block:: bash
salt '*' vault_policy.write salt_minion 'path "secret/foo" {...}'
Required policy:
.. code-block:: vaultpolicy
path "sys/policy/<policy>" {
capabilities = ["create", "update"]
}
policy
Name of the policy to create/update.
rules
Rules to write, formatted as in-line HCL.
"""
endpoint = f"sys/policy/{policy}"
payload = {"policy": rules}
try:
return vault.api_put(endpoint, __opts__, __context__, payload=payload)
except SaltException as err:
raise CommandExecutionError(f"{type(err).__name__}: {err}") from err
[docs]
def delete(policy):
"""
Delete an ACL policy. Returns False if the policy does not exist.
CLI Example:
.. code-block:: bash
salt '*' vault_policy.delete salt_minion
Required policy:
.. code-block:: vaultpolicy
path "sys/policy/<policy>" {
capabilities = ["delete"]
}
policy
Name of the policy to delete.
"""
endpoint = f"sys/policy/{policy}"
try:
return vault.api_delete(endpoint, __opts__, __context__)
except vault.VaultNotFoundError:
return False
except SaltException as err:
raise CommandExecutionError(f"{type(err).__name__}: {err}") from err
[docs]
def list_():
"""
List all ACL policies.
CLI Example:
.. code-block:: bash
salt '*' vault_policy.list
Required policy:
.. code-block:: vaultpolicy
path "sys/policy" {
capabilities = ["read"]
}
"""
try:
return vault.api_get("sys/policy", __opts__, __context__)["policies"]
except SaltException as err:
raise CommandExecutionError(f"{type(err).__name__}: {err}") from err