vault_policy

Runner module equivalent to the vault_policy execution module.

Uses the actual master token to authenticate, not the master-minion one like salt.cmd would use.

Added in version 1.9.0.

Important

This module requires the general Vault setup.

saltext.vault.runners.vault_policy.list_()

List all ACL policies.

CLI Example:

salt-run vault_policy.list

Required policy:

path "sys/policy" {
    capabilities = ["read"]
}
saltext.vault.runners.vault_policy.delete(policy)

Delete an ACL policy. Returns False if the policy does not exist.

CLI Example:

salt-run vault_policy.delete salt_minion

Required policy:

path "sys/policy/<policy>" {
    capabilities = ["delete"]
}
policy

Name of the policy to delete.

saltext.vault.runners.vault_policy.fetch(policy)

Fetch the rules associated with an ACL policy. Returns None if the policy does not exist.

CLI Example:

salt-run vault_policy.fetch salt_minion

Required policy:

path "sys/policy/<policy>" {
    capabilities = ["read"]
}
policy

Name of the policy to fetch.

saltext.vault.runners.vault_policy.write(policy, rules)

Create or update an ACL policy.

CLI Example:

salt-run vault_policy.write salt_minion 'path "secret/foo" {...}'

Required policy:

path "sys/policy/<policy>" {
    capabilities = ["create", "update"]
}
policy

Name of the policy to create/update.

rules

Rules to write, formatted as in-line HCL.