Orkestia
Blog
Vault

Access policies

Decide who may read, use, change or manage which secrets. Owners and admins can do everything; everyone else needs a policy, and deny always wins

Who may do what

  • Organization owners and admins can do everything.
  • Members and Staff agents need an allow policy that matches. If a deny policy matches, they are refused, whatever else allows them.
  • End users of your apps cannot use the Vault.

A personal API token acts as the person who owns it.

Refusals are recorded in the audit log with the reason.

Permissions

PermissionAllows
listSee that the secret exists, never its value
readReveal the value
resolvePass the value to a step in a workflow, without showing it
useCall an API with the secret through API access, without seeing it
writeAdd new versions
deleteDelete and restore versions
destroyErase versions or the whole secret for good
adminManage policies, read the audit log, rotate the key

Permissions are separate. use does not allow reading the value.

use lets the holder do whatever the credential can do on the API it is bound to. Give the credential itself only the permissions it needs at the provider.

Who a policy applies to

principal_kindprincipal_ref
memberA member's user id, or * for every member
roleA role name, such as member or admin
agentA Staff agent's id, or * for every agent

Which secrets

  • * matches one part of a path: aws/*/deploy matches aws/prod/deploy.
  • ** matches any number of parts: aws/** matches everything under aws/.

Write a policy

In the Console: Vault → Policies. From the API: vault.policy.set.

InputMeaning
nameA unique name. Using an existing name replaces that policy
principal_kind, principal_refWho it applies to
path_patternWhich secrets
capabilitiesOne or more permissions from the table above
effectallow (default) or deny
descriptionWhy the policy exists
disabledKeep the policy but stop applying it

vault.policy.list shows your policies and vault.policy.delete removes one.

Examples

Let a Staff agent call GitHub with one token, and nothing else:

{
  "name": "ci-agent-github",
  "principal_kind": "agent",
  "principal_ref": "<agent id>",
  "path_pattern": "github/ci/token",
  "capabilities": ["use"]
}

Let every member see and reveal shared secrets:

{
  "name": "members-shared",
  "principal_kind": "role",
  "principal_ref": "member",
  "path_pattern": "shared/**",
  "capabilities": ["list", "read"]
}

Keep production secrets away from every agent:

{
  "name": "no-agents-on-prod",
  "principal_kind": "agent",
  "principal_ref": "*",
  "path_pattern": "**/prod/**",
  "capabilities": ["read", "resolve", "use", "write", "delete", "destroy"],
  "effect": "deny"
}
Only owners and admins can set API access on a secret. Give admin only to people you would trust as admins.