| Warning |
|---|
Only admins can create new policies (Check EWC Secret Manager - User Roles and Permissions) |
| Table of Contents |
|---|
General
Policies define what a client is allowed to do inside OpenBao. Every token issued by an authentication method (OIDC, AppRole, Kubernetes, etc.) has one or more policies attached. These policies determine the exact capabilities a client has on specific paths within the tenancy namespace.
Policies are written in HCL and are the core mechanism for authorization in OpenBao.
What Policies Do
A policy controls access by specifying:
...