infra/tf/bao-policies/k8s-default.hcl

3 lines
245 B
HCL

path "${k8s_secrets_path}/data/{{identity.entity.aliases.${k8s_auth_backend_accessor}.metadata.service_account_namespace}}/{{identity.entity.aliases.${k8s_auth_backend_accessor}.metadata.service_account_name}}/*" {
capabilities = ["read"]
}