Vault policy path with wildcard

Viewed 1890

I've below policy in vault

path "/secrets/global/*" { capabilities = ["read", "create", "update", "delete", "list"] } 

will this policy grant me access to all the paths under global like

/secrets/global/common/*
/secrets/global/notsocommoon/app1/*
/secrets/global/notsocommoon/app1/module1/*
1 Answers

Yes. Vault will grand all the capabilities to the /secrets/global/ and its child directory.

As we can add multiple paths to the same policy, if we want to restrict few capabilities a particular path, we can do that like

#mypolicy.hcl
path "/secrets/global/*" { capabilities = ["read", "create", "update", "delete", "list"] } 

path "/secrets/global/myteam/passwords/*" { capabilities = ["read"] } 
Related