Use-case module that creates a custom ACL policy for any Vault path and grants it to one workload entity through identity group membership.
Layer
Use-case.
Prerequisites
- The workload module must be applied first so the entity
<cluster_name>-<workload_name> exists in Vault.
| Name |
Type |
Description |
cluster_name |
string |
Cluster identifier, regex validated |
workload_name |
string |
Workload identifier, regex validated |
usecase_name |
string |
Use-case identifier, regex validated |
secret_path |
string |
Vault path expression |
capability_read |
bool |
Read capability flag, default true |
capability_create |
bool |
Create capability flag, default false |
capability_update |
bool |
Update capability flag, default false |
capability_delete |
bool |
Delete capability flag, default false |
capability_list |
bool |
List capability flag, default true |
capability_patch |
bool |
Patch capability flag, default false |
capability_sudo |
bool |
Sudo capability flag, default false |
Outputs
| Name |
Description |
policy_name |
Custom ACL policy name |
group_name |
Identity group name |
No-code notes
- Capability booleans map directly to no-code checkboxes.
- At least one capability must be enabled.
- This module renders no YAML and only creates policy plus identity group resources.
No-code provisioning
This module is no-code enabled in the hc-ric-demo private registry (pinned to 0.2.0). Click Provision workspace, pick a project and workspace name, then complete the form. Capability flags render as checkboxes; at least one must be enabled.
Form fields:
| Field |
Required |
Notes |
cluster_name |
yes |
Cluster identifier |
workload_name |
yes |
Workload identifier |
usecase_name |
yes |
Use-case identifier |
secret_path |
yes |
Vault path expression |
capability_* |
no |
Read/list default true; others default false |
Registry usage
module "add_permission_group" {
source = "app.terraform.io/<org>/add-permission-group/vault"
version = "~> 0.2.0"
cluster_name = "ocp-prod-eu"
workload_name = "payments"
usecase_name = "audit-access"
secret_path = "secret/data/payments/audit/*"
capability_read = true
capability_list = true
capability_create = false
}
This module renders no YAML. It only creates policy and group resources.
Generated by make generate from terraform-vault-onboarding/terraform-vault-add-permission-group. Do not edit by hand.
Requirements
Providers
| Name |
Version |
| vault |
5.10.1 |
Modules
No modules.
Resources
| Name |
Description |
Type |
Default |
Required |
| capability_create |
Whether to grant create capability. |
bool |
false |
no |
| capability_delete |
Whether to grant delete capability. |
bool |
false |
no |
| capability_list |
Whether to grant list capability. |
bool |
true |
no |
| capability_patch |
Whether to grant patch capability. |
bool |
false |
no |
| capability_read |
Whether to grant read capability. |
bool |
true |
no |
| capability_sudo |
Whether to grant sudo capability. |
bool |
false |
no |
| capability_update |
Whether to grant update capability. |
bool |
false |
no |
| cluster_name |
Cluster identifier used in policy and group naming. |
string |
n/a |
yes |
| secret_path |
Vault path expression to grant capabilities on. |
string |
n/a |
yes |
| usecase_name |
Use-case identifier used in policy and group naming. |
string |
n/a |
yes |
| workload_name |
Workload identifier used in policy and group naming. |
string |
n/a |
yes |
Outputs
| Name |
Description |
| group_name |
Identity group name granting the custom policy. |
| policy_name |
Custom ACL policy name. |