Only admins can create new policies (Check EWC Secret Manager - User Roles and Permissions)


General

Policies define what a client is allowed to do inside OpenBao. Every token issued by an authentication method (OIDC, AppRole, Kubernetes, etc.) has one or more policies attached. These policies determine the exact capabilities a client has on specific paths within the tenancy namespace.

Policies are written in HCL and are the core mechanism for authorization in OpenBao.

What Policies Do

A policy controls access by specifying:

Policies do not authenticate users — they only define permissions. Authentication methods issue tokens, and tokens carry policies.


Policy Structure

A typical policy contains one or more path blocks:
Codice
 

path "kv/data/app/*" {
  capabilities = ["read", "list"]
}

path "kv/data/app/config" {
  capabilities = ["create", "update"]
}

Key elements:


Common Capabilities



Where Policies Live

Policies are stored inside the tenancy namespace under:
Codice
 

sys/policies/acl/<policy-name>

They are managed using the CLI or API.


Default policy

By default, every tenancy is provided with two policies for Kubernetes External Secret Operator (ESO):  


You can find these policies in the Policies section:



Create a new policy

1. Write the policy file

Create a file named my-policy.hcl:
Codice
 

path "kv/data/myapp/*" {
  capabilities = ["read", "list"]
}

path "kv/data/myapp/config" {
  capabilities = ["create", "update"]
}

2. Upload the policy to OpenBao

Use the CLI: 

bao policy write my-policy my-policy.hcl

This creates (or updates) the policy named my-policy.

3. Verify the policy 

bao policy read my-policy

4. Attach the policy to an auth method

For example, attach it to an AppRole: 

bao auth approle role write my-role policies="my-policy"