Policies provide a declarative way to grant or forbid access to certain paths and operations in Vault. This tutorial walks through policy creation workflows.
ACL Policy Path Templating
As of 0.11, ACL policies support templating to allow non-static policy paths.
Vault Enterprise supports Sentinel to provide a rich set of access control functionality. This tutorial walks through the creation and use of role governing policies (RGPs) and endpoint governing policies (EGPs).
Sentinel HTTP Import
Vault Enterprise version 1.5 introduced support for the Sentinel HTTP import, which enables use of HTTP-accessible data from outside the runtime. Learn about related Vault server configuration and creating an example Endpoint Governing Policy.
Sentinel Validation Policies
Learn how to write Sentinel policies in Vault Enterprise to ensure specific secrets adhere to certain formats, including policies for ZIP codes, state codes, AWS keys, and Azure credentials.
Vault Enterprise has support for Control Group Authorization which adds additional authorization factors to be required before satisfying a request.