terraform-vault/policies.tf
Ben Vincent 12e04b3db7 feat: add incus-cluster role/policies
- add policy and role to manage incus cluster join tokens
2025-01-06 23:16:06 +11:00

40 lines
997 B
HCL

# Define a list of directories that contain policy files
locals {
policy_directories = [
"policies",
"policies/sys",
"policies/auth/approle",
"policies/auth/ldap",
"policies/auth/token",
"policies/pki_int",
"policies/pki_root",
"policies/rundeck",
"policies/ssh-host-signer",
"policies/sshca",
"policies/kv/service/glauth/services",
"policies/kv/service/incus",
"policies/kv/service/puppetapi",
"policies/kv/service/terraform",
]
}
# Load policy files from each directory
locals {
policy_files = flatten([
for path in local.policy_directories : [
for policy in fileset(path, "*.hcl") : {
name = trim(replace(policy, ".hcl", ""), "/")
path = "${path}/${policy}"
}
]
])
}
# Define Vault policies for all listed directories
resource "vault_policy" "policies" {
for_each = { for policy in local.policy_files : policy.name => policy }
name = each.value.name
policy = file(each.value.path)
}