Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Warning

Only admins can create new policies (Check EWC Secret Manager - User Roles and Permissions)

Table of Contents


General

Policies define what a client is allowed to do inside OpenBao. Every token issued by an authentication method (OIDC, AppRole, Kubernetes, etc.) has one or more policies attached. These policies determine the exact capabilities a client has on specific paths within the tenancy namespace.

Policies are written in HCL and are the core mechanism for authorization in OpenBao.

What Policies Do

A policy controls access by specifying:

...