Files
railiance-platform/openbao/policies/platform-readonly.hcl
2026-05-23 13:59:58 +02:00

29 lines
541 B
HCL

# Read-only platform inspection policy.
#
# Useful for status dashboards and audit/review sessions that need visibility
# into mounts and platform metadata without secret material mutation.
path "sys/health" {
capabilities = ["read"]
}
path "sys/mounts" {
capabilities = ["read", "list"]
}
path "sys/auth" {
capabilities = ["read", "list"]
}
path "sys/policies/acl" {
capabilities = ["read", "list"]
}
path "auth/token/lookup-self" {
capabilities = ["read"]
}
path "platform/metadata/*" {
capabilities = ["read", "list"]
}