Merge pull request 'feat: add templated policies for kubernetes' (#66) from benvin/kubernetes_structured_paths into master

Reviewed-on: #66
This commit was merged in pull request #66.
This commit is contained in:
2026-03-08 12:57:58 +11:00
2 changed files with 22 additions and 0 deletions
@@ -0,0 +1,6 @@
bound_service_account_names:
- default
bound_service_account_namespaces: ['*']
token_ttl: 600
token_max_ttl: 600
audience: vault
+16
View File
@@ -0,0 +1,16 @@
# Templated access to kv secrets for kubernetes
#
# kv/kubernetes/namespace/<namespace>/<service_account>
# kv/kubernetes/cluster/<cluster>/<namespace>/<service_account>
---
rules:
- path: "kv/data/kubernetes/namespace/{{identity.entity.aliases.auth_kubernetes_ac24966b.metadata.service_account_namespace}}/{{identity.entity.aliases.auth_kubernetes_ac24966b.metadata.service_account_name}}/*"
capabilities:
- read
- path: "kv/data/kubernetes/cluster/au/syd1/{{identity.entity.aliases.auth_kubernetes_ac24966b.metadata.service_account_namespace}}/{{identity.entity.aliases.auth_kubernetes_ac24966b.metadata.service_account_name}}/*"
capabilities:
- read
auth:
k8s/au/syd1:
- default