Only admins can create new policies (Check EWC Secret Manager - User Roles and Permissions)
General
Policies define what a client is allowed to do inside OpenBao. Every token issued by an authentication method (OIDC, AppRole, Kubernetes, etc.) has one or more policies attached. These policies determine the exact capabilities a client has on specific paths within the tenancy namespace.
Policies are written in HCL and are the core mechanism for authorization in OpenBao.
What Policies Do
A policy controls access by specifying:
Paths (e.g.,
kv/data/app/config)Capabilities (e.g.,
read,list,update,delete)Constraints (TTL, max TTL, etc.)
Policies do not authenticate users — they only define permissions. Authentication methods issue tokens, and tokens carry policies.
Policy Structure
A typical policy contains one or more path blocks:
Codice
path "kv/data/app/*" {
capabilities = ["read", "list"]
}
path "kv/data/app/config" {
capabilities = ["create", "update"]
}
Key elements:
path — the secret engine path the rule applies to
capabilities — allowed operations
wildcards —
*for multiple items,+for recursive matchingfine‑grained rules — different capabilities for different paths
Common Capabilities
read— retrieve a secretlist— list keyscreate— write a new secretupdate— modify an existing secretdelete— remove a secretsudo— administrative operations
Where Policies Live
Policies are stored inside the tenancy namespace under:
Codice
sys/policies/acl/<policy-name>
They are managed using the CLI or API.
Default policy
By default, every tenancy is provided with two policies for Kubernetes External Secret Operator (ESO):
- read only for mount eso_base_ro
- read write for mount eso_base_rw
You can find these policies in the Policies section:
Create a new policy
1. Write the policy file
Create a file named my-policy.hcl:
Codice
path "kv/data/myapp/*" {
capabilities = ["read", "list"]
}
path "kv/data/myapp/config" {
capabilities = ["create", "update"]
}
2. Upload the policy to OpenBao
Use the CLI:
bao policy write my-policy my-policy.hcl
This creates (or updates) the policy named my-policy.
3. Verify the policy
bao policy read my-policy
4. Attach the policy to an auth method
For example, attach it to an AppRole:
bao auth approle role write my-role policies="my-policy"


