Skip to content

Commit eb8132d

Browse files
authored
Merge pull request #24 from SaiPurnimaPatro/feature/pspatro/v2.0.3
JIRA:MGMTAGENT-7979-Updated new policy for certificate deletion as part of gateway uninstall
2 parents 572864f + b70d6a5 commit eb8132d

File tree

1 file changed

+1
-0
lines changed
  • management-gateway-quickstart

1 file changed

+1
-0
lines changed

management-gateway-quickstart/main.tf

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -60,6 +60,7 @@ module "create_mgmt_gateway_policies" {
6060
"ALLOW DYNAMIC-GROUP ${local.mgmtgateway_dynamic_group_name} TO MANAGE certificate-authorities IN COMPARTMENT ID ${var.policy_compartment_id} where any{request.permission='CERTIFICATE_AUTHORITY_CREATE', request.permission='CERTIFICATE_AUTHORITY_INSPECT', request.permission='CERTIFICATE_AUTHORITY_READ'}",
6161
"ALLOW DYNAMIC-GROUP ${local.mgmtgateway_dynamic_group_name} TO USE certificate-authority-delegates IN COMPARTMENT ID ${var.policy_compartment_id}",
6262
"ALLOW DYNAMIC-GROUP ${local.mgmtgateway_dynamic_group_name} TO MANAGE leaf-certificates IN COMPARTMENT ID ${var.policy_compartment_id} where any{request.permission='CERTIFICATE_CREATE', request.permission = 'CERTIFICATE_INSPECT', request.permission = 'CERTIFICATE_UPDATE', request.permission = 'CERTIFICATE_READ'}",
63+
"ALLOW DYNAMIC-GROUP ${local.mgmtgateway_dynamic_group_name} TO MANAGE leaf-certificates IN COMPARTMENT ID ${var.policy_compartment_id} where all{request.permission='CERTIFICATE_DELETE', target.leaf-certificate.name=request.principal.id}",
6364
"ALLOW DYNAMIC-GROUP ${local.mgmtgateway_credential_group_name} TO USE certificate-authority-delegates in COMPARTMENT ID ${var.policy_compartment_id}",
6465
"ALLOW DYNAMIC-GROUP ${local.mgmtgateway_credential_group_name} TO USE vaults in COMPARTMENT ID ${var.policy_compartment_id}",
6566
"ALLOW DYNAMIC-GROUP ${local.mgmtgateway_credential_group_name} TO USE keys in COMPARTMENT ID ${var.policy_compartment_id}"

0 commit comments

Comments
 (0)