deploy: add "list" operation to Vault policy

Signed-off-by: Niels de Vos <ndevos@redhat.com>
This commit is contained in:
Niels de Vos 2020-11-16 08:32:53 +01:00 committed by mergify[bot]
parent fc9b2e5ac5
commit 04586dc733

View File

@ -82,11 +82,11 @@ items:
# create policy to use keys related to the cluster # create policy to use keys related to the cluster
vault policy write "${CLUSTER_IDENTIFIER}" - << EOS vault policy write "${CLUSTER_IDENTIFIER}" - << EOS
path "secret/data/ceph-csi/*" { path "secret/data/ceph-csi/*" {
capabilities = ["create", "update", "delete", "read"] capabilities = ["create", "update", "delete", "read", "list"]
} }
path "secret/metadata/ceph-csi/*" { path "secret/metadata/ceph-csi/*" {
capabilities = ["read", "delete"] capabilities = ["read", "delete", "list"]
} }
EOS EOS